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Abstract 

The study of belief cfiange has been an active area in philosophy and AI. In recent years 
two special cases of belief change, belief revision and belief update, have been studied in 
detail. In a companion paper (Friedman & Halpern, 1997), we introduce a new framework 
to model belief change. This framework combines temporal and epistemic modalities with a 
notion of plausibility, allowing us to examine the change of beliefs over time. In this paper, 
we show how belief revision and belief update can be captured in our framework. This 
allows us to compare the assumptions made by each method, and to better understand the 
principles underlying them. In particular, it shows that Katsuno and Mendelzon's notion 
of belief update (Katsuno & Mendelzon, 1991a) depends on several strong assumptions 
that may limit its applicability in artificial intelligence. Finally, our analysis allow us to 
identify a notion of minimal change that underlies a broad range of belief change operations 
including revision and update. 



1. Introduction 

The study of belief change has been an active area in philosophy and artificial intelligence. 
The focus of this research is to understand how an agent should change her beliefs as a result 
of getting new information. Two instances of this general phenomenon have been studied 
in detail. Belief revision (Alchourron, Gardenfors, &: Makinson, 1985; Gardenfors, 1988) 
focuses on how an agent should change her (set of) beliefs when she adopts a particular 
new belief. Belief update (Katsuno & Mendelzon, 1991a), on the other hand, focuses on 
how an agent should change her beliefs when she realizes that the world has changed. Both 
approaches attempt to capture the intuition that an agent should make minimal changes 
in her beliefs in order to accommodate the new belief. The difference is that belief revision 
attempts to decide what beliefs should be discarded to accommodate a new belief, while 
belief update attempts to decide what changes in the world led to the new observation.! 



1. Throughout the paper we use "revision" to refer to AGM's proposal for revision (Alchourron et al., 1985) 
not as a generic term for the general approach initiated by AGM; similarly, we use "update" to refer to 
KM's proposal for update (Katsuno & Mendelzon, 1991a). 
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Belief revision and belief update are two of many possible ways of modeling belief change. 
In (Friedman & Halpcrn, 1997), we introduce a general framework for modeling belief 
change. We start with the framework for analyzing knowledge in multi-agent systems, 
introduced in (Halpern k. Fagin, 1989), and add to it a measure of plausibility at each 
situation. We then define belief as truth in the most plausible situations. The resulting 
framework is very expressive; it captures both time and knowledge as well as beliefs. Having 
time allows us to reason in the framework about changes in the beliefs of the agent. It also 
allows us to relate the beliefs of the agent about the future with her actual beliefs in the 
future. Knowledge captures in a precise sense the non-defeasible information the agent has 
about the world, while belief captures the defeasible assumptions implied by her plausibility 
assessment. The framework allows us to represent a broad spectrum of notions of belief 
change. In this paper, we focus on how, in particular, belief revision and update can be 
represented. 

We are certainly not the first to provide semantic models for belief revision and update. 
For example, (Alchourron ct al., 1985; Grove, 1988; Gardenfors &: Makinson, 1988; Rott, 
1991; Boutilier, 1992; de Rijke, 1992) deal with revision, and (Katsuno & Mendelzon, 1991a; 
del Val k. Shoham, 1992) deal with update. In fact, there are several works in the literature 
that capture both using the same machinery (Katsuno & Satoh, 1991; Goldszmidt & Pearl, 
1996; Boutilier, 1998), and others that simulate belief revision using belief update (Grahne, 
Mendelzon, & Rieter, 1992; del Val & Shoham, 1994). Our approach is different from most 
in that we do not construct a specific framework to capture one or both of these belief 
change paradigms. Instead, we start from a natural framework to model how an agent's 
knowledge changes over time and add to it machinery that captures a defeasible notion of 
belief. 

We believe that our representation offers a number of advantages, and gives a deeper 
understanding of both revision and update. For one thing, we show that both revision and 
update can be viewed as proceeding by conditioning on initial prior plausibilities. Thus, 
our representation emphasizes the role of conditioning as a way of understanding minimal 
change. Moreover, it shows that that the major differences between revision and update 
can be understood as corresponding to differences in initial beliefs. For example, revision 
places full belief on the assumption that the propositions used to describe the world are 
static, and do not change their truth value over time. By way of contrast, update allows for 
the possibility that propositions change their truth value over time. However, the family of 
prior plausibilities that we use to capture update in our framework have the property that 
they prefer sequences of events where abnormal events occur as late as possible. Because of 
this property, conditioning in update always "explains" observations by recent changes. The 
fact that time appears explicitly in our framework allows us to make these issues precise. 

In the literature, revision has been viewed as dealing with static worlds (although an 
agent's beliefs may change, the underlying world about which the agent is reasoning does 
not) while update has been viewed as dealing with dynamic worlds (see, for example, (Kat- 
suno k. Mendelzon, 1991a)). We believe that the distinction between static and dynamic 
worlds is somewhat misleading. In fact, what is important for revision is not that the world 
is static, but that the propositions used to describe the world are static. For example, "At 
time the block is on the table" is a static proposition, while "The block is on the table" is 
not, since it implicitly references the current state of affairs. (Note that the assumption that 
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the propositions are static is not unique to belief revision. Bayesian updating, for example, 
makes similar assumptions.) Because we model time explicitly in our framework, we can 
examine this issue in more detail. In fact, in Section |^, we show how we relate these two 
viewpoints. More precisely, given a system, we replace each proposition p used in the system 
by a family of propositions "p is true at time m" , one for each time m. The resulting system 
describes exactly the same process as the original system, but from a different linguistic per- 
spective. As we show, if the original system corresponds to KM update, then the resulting 
system is very close to satisfying the requirements of AGM revision. The only requirement 
that is not met is that the prior is totally ordered, or ranked. This requirement, however, 
has been relaxed in several variants of revision (Katsuno &: Mendelzon, 1991b; Rott, 1992). 
Thus, a large part of the difference between revision and update can be understood as a 
difference in the language used to describe what is happening. 

The generality of our framework forces us to be clear about the assumptions we make 
in the process of capturing revision and update. As a consequence, we have to deal with 
issues that have been largely ignored by previous semantic accounts. One of these issues 
is the status of observations. As we show below, to capture either revision or update, we 
have to assume that observations are minimally informative — the only information carried 
by an observation of ip is that <p should be believed. This is a strong assumption, since 
most observations carry additional information. For example, when trekking in Nepal, 
one does not expect to observe the weather in Boston. If an agent observes that it is in 
fact raining in Boston, then this "observation" might well provide extra information about 
the world (for example, that cable television is available in Nepal). We remark that in 
(Boutilier, Friedman, & Halpern, 1998) there is a treatment of revision in our framework 
where observations are allowed to convey additional information. 

Finally, our representation makes it clear how the intuitions of revision and update 
can be applied in settings where the postulates used to describe them are not sound. For 
example, we consider situations where they may be irreversible changes (such as death, 
or breaking a glass vase), and where the agent may perform actions beyond just making 
observations. Revision and update, as they stand, cannot handle such situations. As we 
show, our framework allows us to extend them in a natural way so they do. 

The rest of the paper is organized as follows. In Section we give an overview of the 
framework we introduced in (Friedman & Halpern, 1997). In Section ^, we give a brief review 
of belief revision and belief update. In Section ^, we define a specific class of structures 
that embody assumptions that are common to both update and revision. In Section |^, 
we describe additional assumptions that are required to capture revision. In Section |6|, we 
describe the assumptions that are required to capture update. In Section |^ we reexamine 
the differences and similarities between belief revision and update. In Section |8|, we consider 
possible extensions to the setup of revision and update, and discuss how these extensions 
can be handled in our framework. Finally, in Section we conclude with a discussion of 
related and future work. 
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2. The Framework 

We now review the framework of Halpern and Fagin (1989) for modeling knowledge, and our 
extension of it for dealing with belief change. The reader is encouraged to consult (Fagin, 
Halpern, Moses, & Vardi, 1995) for further details and motivation. 



2.1 Modeling Knowledge 

The framework of Halpern and Fagin was developed to model knowledge in distributed 
(i.e., multi-agent) systems (Halpern & Fagin, 1989; Fagin et al., 1995). In this paper, we 
restrict our attention to the single agent case. The key assumption in this framework is that 
we can characterize the system by describing it in terms of a state that changes over time. 
Formally, we assume that at each point in time, the agent is in one of a possibly infinite 
set of (local) states. At this point, we do not put any further structure on these states 
(although, as we shall see from our examples, when we model situations in a natural way, 
states typically do have a great deal of meaningful structure). Intuitively, this local state 
encodes the information the agent has observed thus far. There is also an environment, 
whose state encodes relevant aspects of the system that are not part of the agent's local 
state. 

A global state is a pair (sg, Sa) consisting of the environment state Se and the local state 
Sa of the agent. A run of the system is a function from time (which, for ease of exposition, 
we assume ranges over the natural numbers) to global states. Thus, if r is a run, then 
r(0), r(l), ... is a sequence of global states that, roughly speaking, is a complete description 
of what happens over time in one possible execution of the system. Given a run r, we can 
define two functions r^ and that map from time to states of the environment and the 
agent, respectively, by taking re(m) to be the state of the environment in the global state 
r(m) and ra{m) to be the agent's local state in r{m). We can thus identify run r with the 
pair of functions {re,ra)- We take a system to consist of a set of runs. Intuitively, these 
runs describe all the possible behaviors of the system, that is, all the possible sequences of 
events that could occur in the system over time. 

Given a system TZ, we refer to a pair (r, m) consisting of a run r G 7^ and a time m 
as a point. We say two points (r, m) and (r', m') are indistinguishable to the agent, and 
write (r, m) ~a (r', m'), if ra{m) = r'^{m'), i.e., if the agent has the same local state at both 
points. Finally, an interpreted system Z is a tuple (TZ, vr) consisting of a system TZ together 
with a mapping vr that associates with each point a truth assignment to a set $ of primitive 
propositions. In an interpreted system we can talk about an agent's knowledge: the agent 
knows (/9 at a point (r, m) if ip holds in all points {r',m') such that {r,m) ~a {r',m'). 
Intuitively, an agent knows if at (r, m) if ip is implied by the information in the local state 
ra{m). We give formal semantics for a language of knowledge (and time and plausibility) 



in Section 2.3 



Example 2.1: The circuit diagnosis problem has been well studied in the literature (see 
(Davis & Hamscher, 1988) for an overview). Consider a circuit that contains n logical 
components ci , . . . , c„ and k lines /i , . . . , . The agent can set the values on the input lines 
of the circuit and observe the values on the output lines. The agent then compares the actual 
output values to the expected output values and attempts to locate faulty components. 
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Since a single test is usually insufficient to locate the problem, the agent might perform a 
sequence of such tests. 

We want to model diagnosis using an interpreted system. To do so, we need to describe 
the agent's local state, the state of the environment, and some appropriate propositions 
for reasoning about diagnosis. Intuitively, the agent's state is the sequence of input-output 
relations observed, while the environment's state describes the current state of the circuit. 
This consists of the failure set, that is, the set of faulty components of the circuit and the 
values on all the lines in the circuit. Each run describes the results of a specific series of 
tests the agent performs and the results she observes. We make two additional assumptions: 
(1) the agent does not forget what tests were performed and their results, and (2) the faults 
are persistent and do not change over time. 

To make this precise, we define the environment state at a point (r, m) to consist of 
the failure set at {r,m), which we denote fault{r,m), as well as the values of all the lines 
in the circuit. We require that the environment state be consistent with the description 
of the circuit. Thus, for example, if ci is an AND gate with input lines li and I2 and 
output line I3, then if re(m) says that ci is not faulty, then we require that there is a 
1 on I3 if and only if there is a 1 on both li and I2B We capture the assumption that 
faults are persistent by requiring that fault^r^m) = fault{r,0). For our later results, it is 
useful to describe the agent's observations using our logical language. Consider the set 
^diag = {/i; • • • > fn, hi, ... , hk} of primitive propositions, where fi denotes that component 
i is faulty and hi denotes that there is a 1 on line i (that is, line z in a "high" state). An 
observation is a conjunction of literals of the form hi and -i/ij. The agent's state at time 
m is a sequence of m such observations. Formally, we define the agent's state ra{m) to 
be (oi,...,Om), where, intuitively, is the formula describing the input-output relation 
observed at time k. We use the notation io{r, k) to denote the formula describing the 
observation made by the agent at the point {r,k). Given this language, we can define the 
interpretation i^diag in the obvious way. We say that an observation o is consistent with an 
environment state r^. (m) if the states of the input / output lines in r^. (m) agree with these in 
o. The system IZdiag consists of all runs r satisfying these requirements in which io{r, m) is 
consistent with re(m) for all times m. 

Given the system {IZdiag ■,''^diag)i we can examine the agent's knowledge after making a 
sequence of observations oi, . . . ,Om- It is easy to see that the agent knows that the fault set 
must be one with which all the observations are consistent. However, the agent cannot rule 
out any of these fault sets. Thus, even if all the observations are consistent with the circuit 
being fault-free, the agent does not know that the circuit is fault-free, since there might be 
a fault that manifests itself only in configurations that have not yet been tested. Of course, 
the agent might strongly believe that the circuit is fault-free, but we cannot (yet) express 
this fact in our formalism. The next section rectifies this problem. □ 



2. Note that this means that we can recover the behavior of the circuit (although not necessarily its exact 
description) by simply looking at the environment state at a point where there are no failures. Of course, if 
we could have a yet richer environment state that encodes the actual description of the circuit, but this is 
unnecessary for the analysis we do here. 
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2.2 Plausibility Measures 

Most non-probabilistic approaches to belief change require (explicitly or implicitly) that 

the agent has some ordering over possible alternatives. For example, the agent might 
have a preference ordering over possible worlds (Boutilier, 1994b; Grove, 1988; Katsuno & 
Mendelzon, 1991b) or an entrenchment ordering over formulas (Gardenfors &; Makinson, 
1988). This ordering dictates how the agent's beliefs change. For example, in (Grove, 1988), 
the new beliefs are characterized by the most preferred worlds that are consistent with the 
new observation, while in (Gardenfors & Makinson, 1988), beliefs are discarded according 
to their degree of entrenchment until it is consistent to add the new observation to the 
resulting set of beliefs. We represent this ordering using plausibility measures, which were 
introduced in (Friedman &; Halpern, 1995, 1998b). We briefly review the relevant definitions 
and results here. 

Recall that a probability space is a tuple (W,J^, Pi), where 11/^ is a set of worlds, is 
an algebra of measurable subsets of W (that is, a set of subsets closed under union and 
complementation to which we assign probability), and Pr is a probability measure, that is, a 
function mapping each set in to a number in [0, 1] satisfying the well-known probability 
axioms (Pr(0) = 0, Pr(l^) = 1, and Pr(A U B) = Ft{A) + Pr(5), if A and B are disjoint). 

Plausibility spaces are a direct generalization of probability spaces. We simply replace 
the probability measure Pr by a plausibility measure PI, which, rather than mapping sets in 
to numbers in [0, 1], maps them to elements in some arbitrary partially ordered set. We 
read Pl(yl) as "the plausibility of set A\ If Pl(yl) < Pl(-B), then B is at least as plausible 
as A. Formally, a plausibility space is a tuple S = {W, PI), where is a set of worlds, T 
is an algebra of subsets of W , and PI maps sets in T to some domain D of plausibility values 
partially ordered by a relation <£) (so that <£> is reflexive, transitive, and anti-symmetric). 
We assume that D is pointed: that is, it contains two special elements T^j, and A-d such 
that -Ld<d d <D for all d G D; we further assume that Pl(l^) = Td and P1(0) =-Ld- 
As usual, we define the ordering <_d by taking di <d d2 if di <£> and di ^ d2- We omit 
the subscript D from <£,, <£,, T/), and _L£) whenever it is clear from context. 

Since we want a set to be at least as plausible as any of its subsets, we require 

Al If yl C B, then Pl(^) < Pl(5). 

Some brief remarks on this definition: We have deliberately suppressed the domain D 
from the tuple S, since for the purposes of this paper, only the ordering induced by < on 
the subsets in is relevant. The algebra !F also does not play a significant role in this 
paper. Unless we say otherwise, we assume contains all subsets of interest and suppress 
mention of J-, denoting a plausibility space as a pair (14^, PI). 

Clearly plausibility spaces generalize probability spaces. In (Friedman & Halpern, 1998b, 
1995) we show that they also generalize belief function (Shafer, 1976), fuzzy measures (Wang 
& Klir, 1992), possibility measures (Dubois & Prade, 1990), ordinal ranking (or K-ranking) 
(Goldszmidt & Pearl, 1996; Spohn, 1988), preference orderings (Kraus, Lehmann, &; Magi- 
dor, 1990; Shoham, 1987), and parameterized probability distributions (Goldszmidt, Morris, 
Sz Pearl, 1993) that are used as a basis for Pearl's e-semantics for defaults (Pearl, 1989). 

Our goal is to describe the agent's beliefs in terms of plausibility. To do this, we describe 
how to evaluate statements of the form Bip given a plausibility space. In fact, we use a 
richer logical language that also allows us to describe how the agent compares different 
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alternatives. This is the logic of conditionals. Conditionals are statements of the form 
if — read "given 99, ip is plausible" or "given then by default The syntax of the 
logic of conditionals is simple: we start with primitive propositions and close off under 
conjunction, negation and the modal operator — The resulting language is denoted . 

A plausibility structure is a tuple PL = (14/^,P1, vr), where is a set of possible worlds, 
PI is a plausibility measure on W , and 'k{w) is a truth assignment to primitive propositions. 
Given a plausibility structure PL = (W,P1, vr), we define [^^Ipl = {w : ■k{w) \= (p} to 
be the set of worlds that satisfy (p. We omit the subscript PL, when it is clear from the 
context. Conditionals are evaluated according to a rule that is essentially the same as the 
one used by Dubois and Prade (1991) to evaluate conditionals using possibility measures: 

• PL^ ip^%b if either P1(M) =± or Pl{y A VI) > A ^VD- 

Intuitively, (p — holds vacuously if p is impossible; otherwise, it holds if (/? A ^ is more 
plausible than ip A ^iJj. As we show in (Friedman & Halpern, 1998b), this semantics of 
conditionals also generalizes the semantics of conditionals in K-ranking (Goldszmidt & Pearl, 
1996), and PPD structures (Goldszmidt et al., 1993). As we also show in (Friedman & 
Halpern, 1998b), this semantics for conditionals generalizes the semantics of preferential 
structures. As this relationship plays a role in the discussion below, we review the necessary 
definitions here. A preferential structure is a tuple (W,~<,tt), where -< is a partial order 
on W. Roughly speaking, w ~< w' holds if w is preferred to w'B The intuition (Shoham, 
1987) is that a preferential structure satisfies a conditional p — ^ijj if all the most preferred 
worlds (i.e., the minimal worlds according to -<) in [(/?] satisfy ip. However, there may be 
no minimal worlds in fpj. This can happen if [(/?] contains an infinite descending sequence 
. . . ~< W2 ~< wi. What do we do in these structures? There are a number of options: the first 
is to assume that, for each formula p, there are minimal worlds in IpJ; this is the assumption 
actually made in (Kraus et al., 1990), where it is called the smoothness assumption. A yet 
more general definition — one that works even if -< is not smooth — is given in (Lewis, 1973; 
Boutilier, 1994a). Roughly speaking, p — ^ip is true if, from a certain point on, whenever p 
is true, so is V'- More formally, 

{W, -<,7r) satisfies p — ^ip, if for every world wi S {pj, there is a world 11)2 such 
that (a) W2 ^ wi (so that W2 is at least as normal as wi), (b) W2 G A V] , and 
(c) for all worlds -< W2, we have W3 £ {ip ^ ipj (so any world more normal 
than W2 that satisfies ip also satisfies ip). 

It is easy to verify that this definition is equivalent to the earlier one if ~< is smooth. 

Proposition 2.2 : (Friedman & Halpern, 1998b) If ~< is a preference ordering on W, 
then there is a plausibility measure Pl^ on W such that (VF, -<,7r) |= p — ^ip if and only if 

We briefiy describe the construction of Pl^ here, since we use it in the sequel. Given 
a preference order -< on W, let Dq be the domain of plausibility values consisting of one 

3. We follow the standard notation for preference here (Kraus et al., 1990), which uses the (perhaps confusing) 
convention of placing the more likely (or less abnormal) world on the left of the -< operator. Unfortunately, 
when translated to plausibility, this will mean w ^ w' holds iff Pl({iu} > Pl{{'w'}). 
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element d^j for every element w G W. We define a partial order on Dq using ~<: < dw 
\i w < V. (Recall that w < w' denotes that w is preferred to w' .) We then take D to be 
the smallest set containing Dq that is closed under least upper bounds (so that every set 
of elements in D has a least upper bound in D). For a subset A of W , we can then define 
Vl^^A) to be the least upper bound of {d^ : w G A}. Since D is closed under least upper 
bounds, Pl(^) is well defined. As we show in (Friedman & Halpern, 1998b), this choice of 
Pl^ satisfies Proposition |2.2| . 

The results of (Friedman &; Halpern, 1998b) show that this semantics for conditionals 
generalizes previous semantics for conditionals. Does this semantics capture our intuitions 
about conditionals? In the AI literature, there has been little consensus on the "right" 
properties for defaults (which are essentially conditionals). However, there has been some 
consensus on a reasonable "core" of inference rules for default reasoning. This core is usually 
known as the KLM properties (Kraus et al., 1990), and includes such properties as 

AND From (p — and (p — '>-tp2 infer ip — A ■02 

OR From ipi — and tp2 — ^"0 infer ipi V (p2 — >ip 

What constraints on plausibility spaces gives us the KLM properties? Consider the following 
two conditions: 

A2 liA, B, and C are pairwise disjoint sets, Fl{AuB) > P1(C), and Pl(AuC) > 
Pl(5), then Pl(yl) > Pl{B U C). 

A3 If Fl{A) = Fl{B) =_L, then Fl{A U B) =_L. 

A plausibility space (W, PI) is qualitative if it satisfies A2 and A3. A plausibility struc- 
ture (W, PI, vr) is qualitative if (W, PI) is a qualitative plausibility space. In (Friedman & 
Halpern, 1998b), we show that, in a very general sense, qualitative plausibility structures 
capture default reasoning. More precisely, we show that the KLM properties are sound 
with respect to a class of plausibility structures if and only if the class consists of qualita- 
tive plausibility structures. (We also provide a weak condition that we show is necessary 
and sufficient for the KLM properties to be complete.) These results show that plausibility 
structures provide a unifying framework for the characterization of default entailment in 
these different logics. 

2.3 Plausibility and Knowledge 

In (Friedman & Halpern, 1997) we show how plausibility measures can be incorporated into 
the multi-agent system framework of (Halpern & Fagin, 1989). This allows us to describe 
the agent's assessment of the possible states the system is in at each point in time. At the 
same time we also introduce conditionals into the logical language in order to reason about 
these plausibility assessments. We now review the relevant details. 

An (interpreted) plausibility system is a tuple {TZ,tt,V) where, as before, 7^ is a set 
of runs and tt maps each point to a truth assignment, and where V is a plausibility as- 
signment function mapping each point (r, m) to a qualitative plausibility space V{r, m) = 
(^(r,m.)i Pl(r,m))- Intuitively, the plausibility space V{r,m) describes the relative plausibil- 
ity of events from the point of view of the agent at {r,m). In this paper, we restrict our 
attention to plausibility spaces that satisfy two additional assumptions: 
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• W(r,m) = {{r' ,m')\{r,m) ~a {r',m')}. Thus, the agent considers plausible only situa- 
tions that are possible according to her knowledge. 

• if (r, m) ~a {r',m') then V{r,m) = V(x',m'). This means that the plausibility space 
is a function of the agent's local state.Q 

We define a logical language to reason about interpreted systems. The syntax of the logic 
is simple; we start with primitive propositions and close off under conjunction, negation, 
the K modal operator (Kip says that the agent knows f), the Q modal operator {Qip says 
that if is true at the next time step), and the — >■ modal operator. The resulting language 
is denoted £^-^-^.1 We recursively assign truth values to formulas in C^^^ at a point (r, m) 
in a plausibility system Z. The truth of primitive propositions is determined by vr, so that 

(X, r, m) \= p ii TT(r, m){p) = true. 

Conjunction and negation are treated in the standard way, as is knowledge: The agent 
knows if at {r,m) if 99 holds at all points that she cannot distinguish from {r,m). Thus, 

{I,r,m) \= Kip if {I,r',m') \= ip for all {r',m') ~a {r,m). 

Q)ip is true at (r, m) if ip is true at (r, m + 1). Thus, 

(J, r, m) 1= Qip if (J, r, m + 1) |= 

Finally, we define the conditional operator — > to describe the agent's plausibility assessment 
at the current time. Let |v?]{r,m) = {(r',m') G ^^(r-.m) • (X, r, m) |= ip}. 

{I,r,m) \= ip^i} if either Pl(r,m)(M(r,m)) = ^ or Pl(r^„)([(^ A Vl(r,m)) > 'P\r,m){VP A ^V'lCr.m))- 

We now define a notion of belief. Intuitively, the agent believes 99 if 99 is more plausible 
than not. Formally, we define Bip ^ (true — ^ip). 

In (Friedman & Halpern, 1997) we prove that, in this framework, knowledge is an S5 
operator, the conditional operator — >■ satisfies the usual axioms of conditional logic (Burgess, 
1981), and satisfies the usual properties of temporal logic (Manna & Pnueli, 1992). In 
addition, these properties imply that belief is a K45 operator, and the interactions between 
knowledge and belief are captured by the axioms K(p =^ Bcp and B(p =^ KBip. 

Example 2.3: (Friedman &; Halpern, 1997) We add a plausibility measure to the system 



defined in Example grT[ We define Idiag = {'^diag,T^diag,'Pdiag), where Vdiag is the plausi- 
bility assignment we now describe. We assume that failures of individual components are 
independent of one another. If we also assume that the likelihood of each component failing 
is the same, and also that this likelihood is small (i.e., failures are exceptional), then we 
can construct a plausibility measure as follows. If (r',m) and (r",m) are two points in 
^{r,m)) we say that (r',m) is more plausible than {r",m) if \fault{r',m)\ < \fault{r" ,m)\, 



The framework presented in (Friedman & Halpern, 1997) is more general than this, dealing with multiple 
agents and allowing the agent to consider several plausibility spaces in each local state. The simplified 
version we present here suffices to capture belief revision and update. 

It is easy to add other temporal modalities such as until, eventually, since, etc. These do not play a role in 
this paper. 
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that is, if the failure set at {r',m) consists of fewer faulty components than at (r" ,m). We 
extend these comparisons to sets: F\(^r,m){^) ^ Pl(r,m)(-S) if ™iii(r',m)eA(l/^'^^^(^') ^ 
min(j./ ,„)g^(|/ati/^(r', m)|); that is, A is less plausible if all the points in A have failure sets 
of larger cardinality then the minimal one in B. With this plausibility measure, if all of 
the agent's observations up to time m are consistent with there being no failures, then 
the agent believes that all components are functioning correctly. On the other hand, if 
the observations do not match the expected output of the circuit, then the agent considers 
minimal failure sets that are consistent with her observations. Thus, if the observations are 
consistent with a failure of ci, or a failure of C3, or the combined failure of C2 and cj, then 
the agent believes that either ci or C3 is faulty, but not both. 

We now make this more precise. A failure set (i.e., a diagnosis) is characterized by a 
complete formula over /i, . . . , fn — that is, one that determines the truth values all these 
propositions. For example, if n = 3, then /i A-1/2A-1/3 characterizes the failure set {ci}. We 
define D^^^^^-^ to be the set of failure sets (i.e., diagnoses) that the agent considers possible 
at {r,m); that is Di^j.,m) = {f ^ P ■ [^diagif-i'm) \= -^B^f} where F is the set of all possible 
failure sets. 

Belief change in Idiag is characterized by the following proposition. 

Proposition 2.4: // there is some f € D(^r,m) t^c-t consistent with the new observation 
io{r,m + 1), then i?(r,m+i) consists of all the failure sets in -D(r,m) ^^^^ c-fc consistent with 
io(r, m + l). If all f E -D(r,m) o,''^c inconsistent with io{r,m + \), then Di^j.„^j^i-^ consists of all 
failure sets of cardinality j that are consistent with io{r, 1), . . . , io(r, m + 1), where j is the 
least cardinality for which there is at least one failure set consistent with these observations. 

Thus, in Idiag, a new observation consistent with the current set of most likely explanations 
reduces this set (to those consistent with the new observation). On the other hand, a 
surprising observation (one inconsistent with the current set of most likely explanations) 



has a rather drastic effect. It easily follows from Proposition 2.4 that if io{r,m + 1) is 
surprising, then Di^r,m) ^ D{r,m+i) = 0i so the agent discards all her current explanations 
in this case. Moreover, an easy induction on m shows that if D(^r,m) ^ -D(r.,m+i) = 0) then 
the cardinality of the failure sets in -D^,. is greater than the cardinality of failure sets 
in £'(r,m) • Thus, in this case, the explanations in D(^j.,m+i) a-^e more complicated than those 



in ^(r,m)- □ 



2.4 Conditioning 

In an interpreted system, the agent's beliefs change from point to point as her plausibility 
space changes. The general framework does not put any constraints on how the plausibility 
space changes. If we were thinking probabilistically, we could imagine the agent starting 
with a prior on the runs in the system. Since a run describes a complete history over 
time, this means that the agent puts a prior probability on the possible sequences of events 
that could happen. We would then expect the agent to modify her prior by conditioning 
on whatever information she has learned. As we show below, this notion of conditioning is 
closely related to belief revision and update. We remark that we are not the first to applying 
conditioning in the context of belief change (cf. (Goldszmidt & Pearl, 1996; Spohn, 1988)); 
the details are a little more complex in our framework, because we model time explicitly. 
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We start by making the simplifying assumption that we are deahng with synchronous 
systems where agents have perfect recall (Halpern & Vardi, 1989). Intuitively, this means 
that the agent knows what the time is and does not forget the observations she has made. 
Formally, a system is synchronous if (r, m) ~a (r',m') only if m = m'. In synchronous 
systems, the agent has perfect recall if {r',m + 1) ~a (r, m + 1) implies {r',m) {r,m). 
Thus, the agent considers run r possible at the point (r, m + 1) only if she also considers 
it possible at (r, m). This means that any runs considered impossible at (r,m) are also 
considered impossible at (r, m + 1): the agent does not forget what she knew. 

Just as with probability, we assume that the agent has a prior plausibility measure on 
runs that describes her prior assessment on the possible executions of the system. As the 
agent gains knowledge, she updates her prior by conditioning. More precisely, at each point 
(r, m) , the agent conditions her previous assessment on the set of runs considered possible 
at {r,m). This results in an updated assessment (posterior) of the plausibility of runs. This 
posterior induces, via a projection from runs to points, a plausibility measure on points. 
We can think of the agent's posterior at time m as simply her prior conditioned on her 
knowledge at time m. 

Formally, the prior plausibility of the agent is a plausibility measure Va = {'R-, Pla) over 
the runs in the system. If ^ is a set of points, we define 'R-{A) = {r : 3m((r, m) € A)} to be 
the set of runs on which the points in A lie. The agent updates plausibilities by conditioning 
in I if the following condition is met: 

PRIOR There is prior Va = {'R-, Pla) such that for all runs r € TZ, times m, 
and sets A,B C W^r,m), Pl(r,m)(^) < Pl(r,m)(^) if and only if Fla{n{A)) < 

Pla(7^(5)). 

This definition implies that the agent's plausibility assessment at each point is determined, 
in a straightforward fashion, by her prior. 

As shown in (Friedman &: Halpern, 1997), in synchronous systems that satisfy PRIOR 
where agent have perfect recall, we can say even more: the agent's plausibility measure at 
time m + 1 is determined by her plausibility measure at time m. To make this precise, if A 
is a set of points, let prev(74) = {(r, m) : (r, m + 1) € A}. 

Theorem 2.5: (Friedman & Halpern, 1997). Let I be a synchronous system satisfying 
PRIOR where agents have perfect recall. Then Pl(r,m.+i)(^) ^ Pl(r,m+i)(-S) ^/ '^^^ only if 
Pl(r,m)(P'^c^(^)) ^ Pl(r,m)(P''6'^(-S)); foi" ^ll runs r, times m, and sets A,B CI W(^r^jn+i)- 

Thus, in synchronous systems where agents have perfect recall PRIOR implies a "local" 
rule for update that incrementally changes the agent's plausibility at each step. This local 
rule consists of two steps. First, the agent's plausibility at time m is projected to time 
m + 1 points. Second, time m + 1 points that are inconsistent with the agent knowledge at 
(r, m + 1) are discarded. This procedure implies that the relative plausibility of two sets of 
runs does not change unless one of them is incompatible with the new knowledge. 



Example 2.6: It is easy to verify that the system 2diag we consider in Example 2.2 satisfies 
PRIOR. The prior Va is determined by the failure set in each run in a manner similar to 
the construction of Pl(^r,m)- That is, Ri is more plausible than R2 if there is a run in Ri 
with a smaller failure set than all the runs in R2. □ 
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3. Review of Revision and Update 

We now present a brief review of belief revision and update. 

Belief revision attempts to describe how a rational agent incorporates new beliefs. As 
we said earlier, the main intuition is that as few changes as possible should be made. Thus, 
when something is learned that is consistent with earlier beliefs, it is just added to the set of 
beliefs. The more interesting situation is when the agent learns something inconsistent with 
her current beliefs. She must then discard some of her old beliefs in order to incorporate 
the new belief and remain consistent. The question is which ones? 

The most widely accepted notion of belief revision is defined by the AGM theory (Al- 
chourron et al., 1985; Gardenfors, 1988). This theory was originally developed in philosophy 
of science, where one attempts to understand when a scientist changes her beliefs (e.g., the- 
ory of physical laws) in a rational manner. In this context, it seems reasonable to assume 
that the world is static; that is, the laws of physics do not change while the scientist is 
performing experiments. 

Formally, this theory assumes a logical language Ce over a set <l>e of primitive proposi- 
tions with a consequence relation l-£^ that contains the propositional calculus and satisfies 
the deduction theorem. The AGM approach assumes that an agent's epistemic state is 
represented by a belief set, that is, a set K of formulas in the language CeB There is also 
assumed to be a revision operator o that takes a belief set A and a formula (p and returns a 
new belief set Aoip, intuitively, the result of revising A by f. The following AGM postulates 
are an attempt to characterize the intuition of "minimal change": 

(Rl) A o is a belief set 

(R2) ipeAoip 

(R3) Ao^Q Cl{A U {(/?})§ 

(R4) li^if^A then Cl{A U {if}) <ZAoip 

(R5) Ao Lp = C [{false) if and only if ^ip 

(R6) If if <^ip then Ao p = Ao if) 

(R7) Ao{iph^)(Z Cl{A oipu {^}) 

(R8) If ^il; A o ip then Cl{A opU {^}) C A o ((^ A ^). 

The essence of these postulates is the following. After a revision by (p the belief set 
should include ip (postulates Rl and R2). If the new belief is consistent with the belief set, 
then the revision should not remove any of the old beliefs and should not add any new beliefs 
except these implied by the combination of the old beliefs with the new belief (postulates 
R3 and R4). This condition is called persistence. The next two conditions discuss the 
coherence of beliefs. Postulate R5 states that the agent is capable of incorporating any 
consistent belief and postulate R6 states that the syntactic form of the new belief does 
not affect the revision process. The last two postulates enforce a certain coherency on the 

6. For example, Gardenfors (1988, p. 21) says "A simple way of modeling the epistemic state of an individual 
is to represent it by a set of sentences." 

7. Cl{A) — {ifilA V'} is the deductive closure of a set of formulas A. 
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outcome of revisions by related beliefs. Basically, they state that if is consistent with 
A o Lf then Ao [ip Alp) is just Ao oip. 

The notion of belief update originated in the database community (Keller &; Winslett, 
1985; Winslett, 1988). The problem is how a knowledge base should change when something 
is learned about the world. For example, suppose that a transaction adds to the knowledge 
base the fact "Table 7 is in Office 2" , which contradicts the previous belief that "Table 7 
is in Office 1". What else should change? The intuition that update attempts to capture 
is that such a transaction describes a change that has occurred in the world. Thus, in our 
example, by applying update we might conclude that the reason that the table is in Office 
2 is that it was moved, not that our earlier beliefs were false. This example shows that, 
unlike revision, update does not assume that the world is static. 

Katsuno and Mendelzon (1991a) suggest a set of postulates that an update operator 
should satisfy. The update postulates are expressed in terms of formulas, not belief sets. 
That is, an update operator o maps a pair of formulas, one describing the agent's current 
beliefs and the other describing the new observation, to a new formula that describes the 
agent's updated beliefs. This is not unreasonable, since we can identify a formula (p with 
the belief set Cl{ip). Indeed, if $ is finite (which is what Katsuno and Mendelzon assume) 
every belief set A can be associated with some formula 99^ such that Cl{ipA) = ^1 and 
every formula corresponds to a belief set Cl{(p). Thus, any update operator induces an 
operator that maps a belief state and an observation to a new belief state. We slightly 
abuse notation and use the same symbol to denote both types of mappings. We say that 
a belief set A is complete if, for every (p G £g, either (p E A 01 ^ip G A. A formula fx is 
complete if Cl{fj,) is complete. 

The KM postulates are: 

(Ul) h£^^ o ^ 93 

(U2) If f, then l-£^ fiO(p <^ fi 

(U3) \-Ce ^IJ.Of if and only if -.^ or -^ip 

(U4) If \-c^ 111 <^ 112 and h/;^ Lpi <^ cp2 then m o (pi 4^ 112 o <P2 

(U5) he, inoip) => fJ,o{ip Axp) 

(U6) If \-c, fiO(pi ^ (p2 and \-c, fio (p2 ^ (pi, then h^^ fiofi <^ iJ.O(p2 
(U7) If fi is complete then (fi o ipi) A (/x o ip2) =^ lJ,o {ipi V (^2) 
(U8) {ill y 112)0 ip<^ (ill Oip)y {112 o <p). 

The essence of these postulates is as following. After learning 99, the agent believes ip 
(postulate Ul, which is analogous to R2). If 93 is already believed, then updating by ip does 
not change the agent's beliefs (postulate U2, which is a weaker version of R3 and R4). The 
next two postulates (U3 and U4) deal with coherence of the belief change process. They 
are analogous to R5 and R6, respectively, with minor differences. Postulates U5 and U6 
deal with observations that are related to each other. U5 states that beliefs after learning 
if that are consistent with ip are also believed after learning (p Ai/j. U6 states that if ip2 is 
believed after learning ipi and ipi is believed after learning Lp2, then learning either (pi or 
ip2 leads to the same belief set. Finally, U7 and U8 deal with decomposition properties of 
the update operation. U7 states that if is essentially a truth assignment to C, then if ip 
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is believed after learning ip\ and is also believed after learning 992 then it is believed after 
learning (pi y (p2- U8 states that the update of the knowledge base can be computed by 
independent updates on each sub-part of the knowledge. That is, ii /j, = jii V 112, then we 
can apply update to each of //i and H2, and then combine the results. 

4. Belief Change Systems 

We want to model belief change — particularly belief revision and belief update — in the 
framework of systems. To do so, we consider a particular class of systems that we call 
belief change systems. In belief change systems, the agent makes observations about an 
external environment. Just as is (implicitly) assumed in both revision and update, we 
assume that these observations are described by formulas in some logical language. We 
then make other assumptions regarding the plausibility measure used by the agent. We 
formalize our assumptions as conditions BCS1-BCS5, described below, and say that a 
system I = (TZ,n,V) is a belief change system if it satisfies these conditions. We denote by 
qBCS ^]^g Qf belief change systems. 

Assumption BCSl formalizes the intuition that our language includes propositions for 
reasoning about the environment, whose truth depends only on the environment state. 

BCSl The language £ includes a propositional sublanguage £e over a set $e 
of primitive propositions. contains the usual propositional connectives and 
comes equipped with a consequence relation hc^. The interpretation 7r(r, m) 
assigns truth to propositions in $e in such a way that 

(a) 7r(r, m) is consistent with h/;^, that is, {p : p G <I>e, 7r(r, m)(p) = true} U 
{^p : p G <I>e, 7r(r, m)(p) = false} is consistent, and 

(b) 7r(r, m){p) depends only on re{m) for propositions in that is, 7r(r, m){p) = 
7r(r', m')(p) whenever re{m) = r'^{m'). 

Part (b) of BCSl implies that we can evaluate formulas in with respect to environment 
states; that is, if G £e and re{m) = r'^{m'), then (X, r, m) \= (p if and only if (X, r', m!) \= (p. 
Since the environment is all that is relevant for formulas in >Ce, if <^ G we write Se\= ^ 
if {I,r,m) \= (p for some point (r.rn) such that r^^m) = Sg. 

BCS2 is concerned with the form of the agent's local state. Recall that, in our framework, 
the local state captures the relevant aspects of the agent's epistemic state. The functional 
form of the revision and update operators suggests that all that matters regarding how an 
agent changes her beliefs are the agent's current epistemic state (which is taken by both 
AGM and KM to be a belief set) and what is learned. In terms of our framework, this 
suggests that agent's local state at time m + 1 should be a function of her local state of 
time m and the observation made at time m. We in fact make the stronger assumption 
here that the agent's state consists of the sequence of observations made by the agent. This 
means that the agent remembers all her past observations. Note that this surely implies 
that the agent's local state at time m + 1 is determined by her state at time m and the 
observation made at time m. We make the further assTimption that the observations made 
by the agent can be described by formulas in Ce. Although this is quite a strong assumption 
on the expressive power of Ce, it is standard in the literature: both revision and update 
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assume that observations can be expressed as formulas in the language (see Section |3|). 
These assumptions are formalized in BCS2: 

BCS2 For all r E i? and for all m, we have ra{m) = (0(^1), . . . , 0(^r,m)) where 
0(^r,k) S Ce for 1 < k < m. 

Intuitively, o^r,k) is the observation the agent makes immediately after the transition from 
time A: — 1 to time k in run r. Thus, it represents what the agent observes about the new 
state of the system at time k. Note that BCS2 implies that the agent's state at time is the 
empty sequence in all runs. Moreover, it implies that ra{m + 1) = ra{m) ■ 0(r,m+i)) where • 
is the append operation on sequences. That is, the agent's state at (r, m + 1) is the result 
of appending to her previous state the latest observation she has made about the system. 
It is not too hard to show that belief change systems are synchronous and agents in them 
have perfect recall. (We remark that the agents' local states are modeled in a similar way 
in the model of knowledge bases presented in (Fagin et al., 1995).) 

Clearly we want to reason in our language about the observations the agent makes. 
Thus, we assume that the language includes propositions that describe the observations 
made by the agent. 

BCS3 The language £ includes a set $o6s of primitive propositions disjoint 
from $e such that <I>obs = {learn{ip) : ip E Ce\- Moreover, Tr{r,m){learn{if)) = 
true if and only if 0(^ ,„) = (/? for all runs r and times m. 

In a system satisfying BCS1-BCS3, we can talk about belief change. The agent's state 
encodes observations, and we have propositions that allow us to talk about what is observed. 
The next assumption is somewhat more geared to situations where observations are always 
"accepted" , so that after the agent observes tp, she believes ip. While this is not a necessary 
assumption, it is made by both belief revision and belief update. We capture this assumption 
here in what is perhaps the simplest possible way: by assuming that observations are 
reliable, so that the agent observes ip only if the current state of the environment satisfies 
ip. This is certainly not the only way of enforcing the assumption that observations are 
accepted, but it is perhaps the simplest, so we focus on it here. As we shall see, this 
assumption is consistent with both revision and update, in the sense that we can capture 
both in systems satisfying it. 

BCS4 {I,r,m) ^ 

'^{r,m) runs r and times m. 

Note that BCS4 implies that the agent never observes false. Moreover, it implies that after 
observing ip, the agent knows that ip is true. In (Boutilier et al., 1998), we consider an 
instance of our framework in which observations are unreliable (so that BCS4 does not hold 
in general), and examine the status of R2, the acceptance postulate, in this case. 

Finally, we assume that belief change proceeds by conditioning. While there are certainly 
other assumptions that can be made, as we have tried to argue, conditioning is a principled 
approach that captures the intuitions of minimal change, given the observations. And, as 
we shall see, conditioning (as captured by PRIOR) is consistent with both revision and 
update. 

BCS5 I satisfies PRIOR. 
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Many interesting systems can be viewed as BCS's. 



Example 4.1: Consider the systems Idiag,! and 2diag,2 of Example 2.1. Are these systems 
BCSs? Not quite, since vr^jag is not defined on primitive propositions of the form learn{ip), 
but we can easily embed both systems in a BCS. Let Cdiag the propositional language defined 
over ^diag, and let ^Jj^^ consist of ^diag together with all the primitive propositions of the 
form learn(ip) for cp E Cdiag- Let T^diag be the obvious extension of TTdiag to ^diag^ defined so 
that BCSS holds. Then in it is easy to see that {'R-diag-.T^^ag-''^ diag,i) is a BCS: we take the 
$e of BCSl to be $ diag, and define l~£^jjj^ so that it enforces the relationships determined 
by the circuit layout. Thus, for example, if ci is an AND gate with input lines li and I2 
and output line /s, then we would have ~^fi =^ (^3 <^ hi Ah2). It is then easy to see 

that BCS2-BCS5 hold by our construction. □ 

These definitions set the background for our presentation of belief revision and belief 
update. 



5. Capturing Revision 

Revision can be captured by restricting to BCSs that satisfy several additional assump- 
tions. Before describing these assumptions, we briefly review a well-known representation 
of revision that will help motivate them. 

While there are several representation theorems for belief revision, the clearest is perhaps 
the following (Grove, 1988; Katsuno & Mendelzon, 1991b). We associate with each belief 
set A a set Wa of possible worlds that consists of those worlds where A is true. Thus, an 
agent whose belief set is A believes that one of the worlds in Wa is the real world. An agent 
that performs belief revision behaves as though in each belief state A she has a ranking, 
i.e., a total preorder, over all possible worlds such that the minimal (i.e., most plausible) 
worlds in the ranking are exactly those in Wa- When revising by (p, the agent chooses the 
minimal worlds satisfying 93 in the ranking and constructs a belief set from them. It is easy 
to see that this procedure for belief revision satisfies the AGM postulates. Moreover, in 
(Grove, 1988; Katsuno & Mendelzon, 1991b), it is shown that any belief revision operator 
can be described in terms of such a ranking. 

This representation suggests how we can capture belief revision in our framework. We 
define C Q^^s j^g ^.j-^g q£ belief change systems T = {JZ, vr, V) that satisfy the 
conditions REV1-REV4 that we define below. 

Revision assumes that the world does not change during the revision process. For- 
mally this implies that propositions in $e do not change their truth value along a run, 
i.e., (X, r, m) \= p if and only if (X, r, m + 1) \= p for all p G <I>e- This says that the state of 
the world is the same with respect to the properties that the agent reasons about (i.e., the 
propositions in $e). 

REVl TT{r,m){p) = 7r(r, 0)(p) for all p E <I>e and points {r,m). 

Note that REVl does not necessarily imply that re(m) = re{m + 1). That is, REVl allows 
for a changing environment. The only restriction is that the truth value of propositions 
that describe the environment does not change. We return to this issue in Section ^. 
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The representation of (Grove, 1988; Katsuno & Mendelzon, 1991a) requires the agent 
to totahy order possible worlds. We put a similar requirement on the agent's plausibility 
assessment. Recall that BCS5 says that the agent's plausibility is induced by a prior Pl^; 
REV2 strengthens this assumption. 

REV2 The prior Pl^ of BCS5 is ranked; that is, for all A,B <Z 11, either 
Pla(^) < Pla(5) or Pla(-B) < Pla(^), and V\{AUB) = max(Pl(A),Pl(S)). 

The representation of (Grove, 1988; Katsuno & Mendelzon, 1991a) also requires that 
the agent considers all truth assignments possible. We need a similar condition, except that 
we want not only that all truth assignments be considered possible, but that they have 
nontrivial plausibility (i.e., are more plausible than _L) as well. 

To make this precise, it is helpful to introduce some notation that will be useful for our 
later definitions as well. Given a system Z and two sequences 991, . . . , 99^ and oi, . . . , o^/ 
of formulas in Ce-, let TZ[ipi, . . . ,ipk',oi, . . . , Ok'] consist of all runs r where for each i with 
I < i < k, the formula ipi is true at (r, i) and the agent observes oi,...,Ofc'. That is, 
Tl[ipo, . . . ,ipk]Oi,. . .,Ok'] = {r £ I : {I,r,i) \= ipi,i = 0, . . . , k, and ra{k') = (oi, . . . ,Ofc')}. 
We allow either sequence of formulas to be empty, so, for example, TZlip; ■] consists of all 
runs for which (p is true at the initial state. (Note that if REVl holds, this means that (/? is 
true in all subsequent states as well.) We use the notation TZ[ipi, . . . , ipm] as an abbreviation 
for Tl[ipi, . . .,^m\ •]• 

REVS If 99 G £e is consistent, then Pla(7^ [(/?]) > ±. 

It might seem that REV1-REV3 capture all of the assumptions made by the representa- 
tion of (Grove, 1988; Katsuno & Mendelzon, 1991a). However, there is another assumption 
implicit in the way revision is performed in these representations that we must make explicit 
in our representation, because of the way we have distinguished observing 99 (captured by 
the formula learn{ip)) from 99 itself. Intuitively, when the agent observes 99, she updates her 
plausibility assessment by conditioning on 99. This is essentially what we can think of the 
earlier representations as doing. However, in our representation, the agent does not condi- 
tion on 99, but on the fact that she has observed if. Although we do require that 9? must 
be true if the agent observes it (BCS4), the agent may in general gain extra information by 
observing 99. 

To understand this issue, consider the following example. Suppose that TZ is such that 
the agent observes pi at time (r, m) only if p2 and q are also true at (r, m) , and she observes 
pi A p2 at (r, m) only if q is false. It is easy to construct a BCS satisfying REV1~REV3 
that also satisfies these requirements. In this system, after observing pi, the agent believes 
P2 and q. According to AGM's postulate R7 (and also KM's postulate U5) the agent must 
believe q after observing pi A p2- To see this, note that our assumptions about TZ can 
be phrased in the AGM language as p2 /\ q S K o pi and ^q G K o [pi A p2)- Postulate 
R7 states that K o (pi A P2) C Cl{K o pi \J {^2})- Since p2 £ K o pi, we have that 
Cl{K opiU {p2 } ) = Kopi. Thus , R7 implies in this case that q^ K o{pi Ap2)- However , in 
TZ, the agent believes (indeed knows) -^q after observing pi A p2-^ Thus, revision and update 

8. We stress this does not mean that p\ Ap2 implies -^q in TZ. There may well be points in 71 at which pi Ap2 Ag 
is true. However, at such points, the agent would not observe pi Ap2, since the agent observes pi Ap2 only 
if q is false. 



133 



Friedman & Halpern 



both are implicitly assuming that the observation of ip does not provide such additional 
knowledge. The following assumption ensures that this is the case for revision (a more 
general version will be required for update; see Section ^). 

REV4 Pla(7^[(p; oi, . . . , o^]) > Pla(7^[V'; oi, . . . , o^]) if and only if V\a{n[p A 

Oi A . . . A Om]) > Pla(7^[V' A Oi A ... A Om]). 

This assumption captures the intuition that observing oi , . . . , provides no more in- 
formation than just the fact that oi A . . . A Om is true. That is, the agent compares the 
plausibility of and ip in the same way after conditioning by the observations oi, . . . ,Om 
as after conditioning by the fact that oi A . . . A Om is true. It easily follows from REV4 and 
PRIOR that the agent believes ^p after observing oi A . . . A exactly if oi A . . . A Om A V' 
was initially considered more plausible than oi A . . . A Om A -^ip. Thus, the agent believes ^p 
after observing oi A . . . A Om exactly if initially, she believed ^ conditional on oi A . . . A 0^: 
the observations provide no extra information beyond the fact that each of the Oj's are true. 

REV4 is quite a strong assumption. Not only does it say that observations do not 
give the agent any additional information (beyond the fact that they are true), it also says 
that all consistent observations can be made (since if </? A o is consistent, we must have 
Pla(7^[99;o]) = Pla(7^[l^ A o]) > 1, by REVS and REV4). We might instead consider using 
a weaker version of REV4 that says that, provided an observation can be made, it gives no 
additional information. Formally, this would be captured as 

REV4' lfPla{n[ip; oi, . . . , o^]) > 0, then Pla(7^[(^; oi, . . . , o^]) > Pla{n[t, oi, . . . , o^]) 
if and only if Pla(7^[v9 A oi A ... A Om]) > Pla(^[V' A oi A ... A o^]). 

The following examples suggests that REV4' may be more reasonable in practice than 
REV4. We used REV4 only because it comes closer to the spirit of the requirement of 
revision that all observations are possible. 



Example 5.1: Consider the system Xdiag,! described in Example 2.1. As discussed in Ex- 



ample |4j, this system can be viewed as a BCS. Is it a revision system? It is easy to see that 
Xdiag,i Satisfies REV2 and REVS. It clearly does not satisfy REVl, since propositions that 
describe input/output lines can change their values from one point to the next. However, 
as we are about to show, a slight variant olIdiag,i does satisfy REVl. A more fundamental 
problem is that Idiag,i does not satisfy REV4. This is inherent in our assumption that the 
agent never directly observes faults, so that, for example, we have Pldiag,i{T^l'i fi]) = -L, 
while Pl(iiag,i('^[/i]) > -L. It does, however, satisfy REV4'. 

To see how to modify Idiag,i so as to satisfy REVl, recall that in the diagnosis task, the 
agent is mainly interested in her beliefs about faults. Since faults are static in Idiag,i, we can 
satisfy REVl if we ignore all propositions except /i, . . . , /„. Let ^'^iag = {/i) • • • > fn} and let 
^'diag ^6 the propositional language over ^'^iag- For every observation o made by the agent 
regarding the value of the lines, there corresponds a formula in C'^^^^g that characterizes all 
the fault sets that are consistent with o. Thus, for every run r in Idiag,!^ we can construct 
a run r' where the agent's local state is a sequence of formulas in C'^i^g. Let I'^iag be the 
system consisting of all such runs r' . We can clearly put a plausibility assignment on these 
runs so that Idiag,i and I'^iag are isomorphic in an obvious sense. In particular, the agent 
has the same beliefs about formulas in vC'^j^g at corresponding points in the two systems. 
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More precisely, if ip e C'^^^g, then {I'^^^g,r,m) \= cp if and only if {Idiag,i,r,m) \= ip for all 
points (r, TTij in Idiag^x- It is Gasy to verify tlicit '^[ij^Q^g satisfies REV1-REV3 and REV4', 
although it still does not satisfy REV4. 

We are not advocating here here using I'^^^^g instead of Idiag — ^diag seems to us a perfectly 
reasonable way of modeling the situation. Rather, the point is that if we want a BCS to 
satisfy properties that validate the AGM postulates, we must make some strong, and not 
always natural, assumptions. □ 

We want to show that a revision operator corresponds to a system in and vice 
versa. To do so, we need to examine the beliefs of the agent at each point (r, m). First 
we note that if (r, m) ~a (r', m') then (X, r, m) |= Bip if and only if (I, r', m') \= Bp; 
this is a consequence of the requirement that, as we have defined interpreted systems, the 
agent's plausibility assessment is a function of her local state. Thus, we think of the agent's 
beliefs as a function of her local state. We use the notation (X, Sa) \= Bp as shorthand for 
{I,r,m) \= Bp for some {r,m) such that ra{m) = Sa- Let Sa be some local state of the 
agent. We define the agent's belief state at Sa as 

Bel(X, Sa) = {peCe: (X, ^ Bp}. 

Since the agent's state is a sequence of observations, the agent's state after observing p is 
simply Sa ■ p, where • is the append operation. Thus, Bel(X, Sa • p) is the belief state after 
observing p. We adopt the convention that if the agent can never attain the local state Sa 
in X, then Bel(X, Sa) = Ce- With these definitions, we can compare the agent's belief state 
before and after observing p, that is Bel(X, Sa) and Bel(X, Sa- p)- 

We start by showing that every AGM revision operator can be represented in C^. 

Theorem 5.2: Let o he an AGM revision operator and let K Q Ce be a consistent belief 
state. Then there is a system To^k £ such that Bel{2o^K, {)) = K and 

Bel{Io,K, 0)°^ = Bel{Io,K, {p)) 

for all p £ Ce- 



Proof: See Appendix A.l. □ 



Thus, Theorem ^.2| says that we can represent a revision operator o in the sense that we 
have a family of systems Io,k £ C^, one for each consistent belief state K, such that K is 
the agent's initial belief state in Io,k, and for each formula p in Ce, the agent's belief state 
after learning p is K o p. Notice that we restrict attention to consistent belief states K. 
The AGM postulates allow the agent to "escape" from an inconsistent state, so that K o p 
may be consistent even if K is inconsistent. We might thus hope to extend the theorem so 
that it also applies to the inconsistent belief state, but this is impossible in our framework. 
If false € Bel(Xo,_ft-, Sa) for some state Sq, and ra{m) = Sa, then Pl(r,m)(^(r,m)) = -L- Since 
we update by conditioning, we must have Pl(r,m+i)(W^(r,m+i)) = -L, so the agent's belief 
state will remain inconsistent no matter what she learns. Although we could modify our 
framework to allow the agent to escape from inconsistent states, we actually consider this 
to be a defect in the AGM postulates, not in our framework. To see why, suppose that the 
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agent's belief set is inconsistent at Sa, and ra{m) = Sa- Thus, the agent considers all states 
in W(^j.,m) to be completely implausible (since Pl(r,m)(^(r,m)) = -L)- On the other hand, to 
escape inconsistency, she must have a plausibility ordering over the worlds in TV(r,m) • These 
two requirements seem somewhat inconsistent. El 

Not surprisingly, this inconsistency creates problems for other semantic representations 
in the literature. For example, Boutilier's representation theorem (1992) states that for 
every revision operator o and belief state K, there is a ranking R such that ip £ K o(p if and 
only if ip is believed in the minimal c/j- worlds according to R. If we examine this theorem, we 
note that he does not state that the minimal (i.e., most preferred) worlds in R correspond 
to the belief state K (in the sense that the minimal worlds are precisely those where the 
formulas in K hold); this would be the analogue of our requiring that Bel{Io,K, ()) = K. 
In fact, if K is h^^-consistent, the minimal worlds do correspond to K. However, if K is 
inconsistent, they cannot, since any nonempty ranking induces a consistent set of beliefs. 
We could state a weaker version of Theorem that would correspond exactly to Boutilier's 
theorem. We presented the stronger result (that does not apply to inconsistent belief states) 
to bring out what we believe to be a problem with the AGM postulates. See (Friedman & 
Halpern, 1998a) for further discussion of this issue. 

Theorem ^.2| shows that, in a precise sense, we can map AGM revision operations to 
C^. What about the other direction? The next theorem shows that the first belief change 
step in systems in satisfies the AGM postulates. 

Theorem 5.3: Let Z be a system in C^. Then there is an AGM revision operator oj such 
that 

Bel{I, 0) ox ^ = Bel{I, (^)) 

for all if £ Ce- 



Proof: See Appendix A.l. □ 



We remark that if we used REV4' instead of REV4, then we would be able to prove this 
result only for those formulas (p that are observable (i.e., for which Pl(7^[(/9]) > _L). 

Both Theorems ^.2| and |5.3| apply to one-step revision, starting from the initial (empty) 
state. What happens once we allow iterated revision? In our framework, observations are 
taken to be known, so if the agent makes an inconsistent sequence of observations, then her 
belief state will be inconsistent, and (as we observed above) will remain inconsistent from 
then on, no matter what she observes. This creates a problem if we try to get analogues to 



Theorems |5.2| and for iterated revision. As the following theorem demonstrates, we can 
already see the problem if we consider one-step revisions from a state other than the initial 
state. 

Theorem 5.4: Let I be a system in and let Sa = {^i, ... ,(pk) be a local state in I. 
Then there is an AGM revision operator oj such that 

Bel{I, Sa) oj^sa f = Bel{I, Sa ■ ^) 



9. One strength of the AGM framework is that it can deal with an inconsistent sequence of observations, that 
is, it can cope with an observation sequence of the form {p,^p,p,^p, . . .). We stress that being able to 
cope with such an inconsistent sequence of observations does not require allowing the agent to escape from 
inconsistent belief sets. These are two orthogonal issues. 
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for all formulas if (z Ce such that A . . . A 99^ A 9? is consistent. 



Proof: See Appendix |A.l| . □ 



We cannot do better than this. If A ... A (^^ A 99 is inconsistent then, because of 
our requirements that ah observations must be true of the current state of the environment 
(BCS4) and that propositions are static (REVl), there cannot be any global state in I 
where the agent's local state in Sa ■ <f- Thus, Bel(X, Sa ■ ^) is inconsistent, contradicting R5. 



There is another problem with trying to get an analogue of Theorem 5.3 for iterated 
revision, a problem that seems inherent in the AGM framework. Our framework makes a 
clear distinction between the agent's epistemic state at a point (r, m) in X, which we can 
identify with her local state Sa = ra{m), and the agent's belief set at {r,m), Bel(T, Sa), 
which is the set of formulas she believes. In a system in C^, the agent's belief set does 
not in general determine how the agent's beliefs will be revised; her epistemic state does. 
On the other hand, the AGM postulates assume that revision is a function of the agent's 
belief set and observations. Now suppose we have a system I and two points (r, m) and 
{r,m') on some run r ^ Z such that (1) the agent's belief set is the same at {r,m) and 
{r,m'), that is Bel(Z, ra(m)) = Bel{I,ra{m')), (2) the agent observes ip at both {r,m) and 
(r, m'), (3) Bel(T, ra{m + 1)) 7^ Bel(X, ra{m' + 1). It is not hard to construct such a system 



I. However, there cannot be an analogue of Theorem 5.2 for Z, even if we restrict to 
consistent sequences of observations. For suppose there were a revision operator o such 
Bel(X, ())) o ipi o ■ ■ ■ o ipi^ = Bel(X, {ipi, . . . , ipk)) for all ipi, . . . , such that A . . . A yj^ is 
consistent. Then we would have Bel(T, ra{m + l)) = Bel(X, ra{m))oip = Bel(T, ra{m'))oip = 
Bel(X, ra(m' + 1)), contradicting our assumption. 

The culprit here is the assumption that revision depends only on the agent's belief set. 
To see why this is an unreasonable assumption, consider a situation where at time the 
agent believes both p and g, but her belief in q is stronger than her belief in p (i.e., the 
plausibility of q is greater than that of p) . We can well imagine that after observing -ip V -ig 
at time 1, she would believe ^p and q. However, if she first observed p at time 1 and then 
^pV^q at time 2, she would believe p and -^q, because, as a result of observing p, she would 
assign p greater plausibility than q. Note, however, that the AGM postulates dictate that 
after an observation that is already believed, the agent does not change her beliefs. Thus, 
the AGM setup would force the agent to have the same beliefs after learning -ip V ^q in 
both situations. 

There has been a great deal of work on the problem of iterated belief revision (Boutilier, 
1996a; Darwiche & Pearl, 1997; Preund & Lehmann, 1994; Lehmann, 1995; Levi, 1988; 
Nayak, 1994; Williams, 1994)). Much of the recent work moves away from the assumption 
that belief revision depends solely on the agent's belief set. For example the approaches 
of Boutilier (1996a) and Darwiche and Pearl (1997) define revision operators that map 
(rankings x formulas) to rankings. Because our framework makes such a clear distinction 
between epistemic states and belief states, it gives us a natural way of maintaining the 
spirit of the AGM postulates while assuming that revision is a function of epistemic states. 
Rather than taking o to be a function from (belief states x formulas) to belief states, we 
take it o to be a function from (epistemic states x formulas) to epistemic states. 

This leaves open the question of how to represent epistemic states. Boutilier and Dar- 
wiche and Pearl use rankings to represent epistemic states. In our framework, we represent 
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epistemic states by local states in interpreted systems. That is, a pair (X, Sa) denotes the 
agent's state in an interpreted system, and the pair determines the agent's relevant epis- 
temic attitudes, such as her beliefs, how her beliefs changed given particular observations, 
her plausibility assessment over runs, and so on. When the system is understood, we simply 
use Sa as a shorthand representation of an epistemic state. 

We can easily modify the AGM postulates to deal with such revision operators on 
epistemic states. We start by assuming that there is a set of epistemic states and a function 
Bel(-) that maps epistemic states to belief states. We then have analogues to each of the 
AGM postulates, obtained by replacing each belief set by the beliefs in the corresponding 
epistemic state. For example, we have 

(Rl') o is an epistemic state 

(R2') if G Bel(£; o cp) 

(R3') Bel{E oip)C Cl{Bel{E) U {ip}) 

and so on, with the obvious transformation. 

We can get strong representation theorems if we work at the level of epistemic states. 
Given a language Cg (with an associated consequence relation let Sc^ consist of all 

finite sequences of formulas in Cg- Note that we allow to include sequences of formulas 
whose conjunction is inconsistent. We define revision in £ce ™ the obvious way: if G £c^, 
then E o (p = E ■ ip. 

Theorem 5.5: Let T be a system in whose local states are Sc^. There is a function 
Belj that maps epistemic states to belief states such that 

• if Sa is a local state of the agent in I, then Bel{Z,Sa) = Belj{sa), and 

• {o,Belj) satisfies Rl' -R^ . 

Proof: Roughly speaking, we define Belx(sa) = Bel(T, Sa) when Sa is a local state in I. If 
Sa is not in X, then we set Belj(sa) = Bel(X, s'), where s' is the longest consistent suffix of 
Sa- See Appendix |A.l for details. □ 



Notice that, by definition, we have Belx(X, () oj y?i oj . . . oj c^^,) = Beli(X, {ipi, . . . , ipk))i 
so, at the level of epistemic states, we get an analogue to Theorem [5.3| . We remark that to 
ensure that R5' holds for (o,Belj), we need to define Belx(-E') appropriately for sequences 
-E G f I whose conjunction is inconsistent. 

Theorem 5.5 shows that any system in corresponds to a revision operator over 
epistemic states that satisfies the generalized AGM postulates. We would hope that the 
converse also holds. Unfortunately, this is not quite the case. There are revision operators 
on epistemic states that satisfy the generalized AGM postulates but do not correspond to 
a system in C^. This is because systems in satisfy an additional postulate: 

(R9') If -^{^ A V) then Bel{E o o ^) = Bel{E oipA^p). 



10. The only problematic postulate is R6. The question is whether R6' should be "If l-£^ if <^ ip then 'Bte\{Eoip) = 
Bel(i5 o or "If \-c^ then E o ip = E o ip" . Dealing with either version is straightforward. For 

definiteness, we adopt the first alternative here. 
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We show that R9' is sound in by proving the following strengthening of Theorem 5.5 



Proposition 5.6: Let T he a system in whose local states are £c^. There is a function 
Belj that maps epistemic states to belief states such that 

• if Sa is a local state of the agent in I, then Bel{I,Sa) = Belx{sa), cmd 

• {o,Belx) satisfies Rl' . 



Proof: We show that the function Belj defined in the proof of Theorem 5.5 satisfies R9'. 
See Appendix |A.l for details. □ 



We can prove the converse to Proposition 5.6: a revision system on epistemic states that 



satisfies the generalized AGM postulates and R9' does correspond to a system in C^. 

Theorem 5.7: Given a function Belc^ mapping epistemic states in £c^ to belief sets over 
Ce such that Belc^{{)) is consistent and {Belc^, o) satisfies Rl'-R9' , there is a system! € 
whose local states are in £c^ such that Belc^{sa) = Bel{sa) for each local state Sain I. 



Proof: According to Theorem 5.2, there is a system 2 such that Bel(T, ()) = Belc^{{)) 
and Bel(X, (ip)) = Belc^{{^)) for all ip € Ce- We show that Bel(T, Sq) = Bel£^ (sa) for local 
states Sa in I. See Appendix |A.l . 



□ 



Notice that, by definition, for the system T of Theorem we have Bel(()o(^;^o. . .o(^^) = 
Bel(((^i, . . . , ipk)) as long as A . . . A is consistent. 

6. Capturing Update 

Update tries to capture the intuition that there is a preference for runs where all the 
observations made are true, and where changes from one point to the next along the run 
are minimized. 

We start by reviewing Katsuno and Mendelzon's semantic representation of update. To 
characterize an agent beliefs, Katsuno and Mendelzon consider the set of "worlds" the agent 
considers possible. In their representation, they associate a world with a truth assignment to 
the primitive propositions. (In our terminology, we can think of a world as an environment 
state.) To capture the notion of "minimal change from world to world", Katsuno and 
Mendelzon use a distance function d on worlds. Given two worlds w and w' , d{w,w') 
measures the distance between them. Intuitively, the larger the distance, the larger the 
change required to get from world w to w' . (Note that that distances are not necessarily 
symmetric, that is, it might require a smaller change to get from w to w' , than from w' 
to w.) Distances might be incomparable, so we require that d map pairs of worlds into a 
partially ordered domain with a unique minimal element and that d{w, w') = if and only 
if w = w' . 

Katsuno and Mendelzon show that there is a close relationship between update operators 
and distance functions. To make this relationship precise, we need to introduce some 
definitions. An update structure is a tuple U = (VF, d, vr), where is a finite set of worlds, 
d is a distance function on W, and vr is a mapping from worlds to truth assignments for Cg 
such that 
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• Tr{w) is consistent, 

• if \/cg -!</?, then there is some w eW with -ir{w){(p) = true, and 

• if w ^ w' then Tr{w) ^ Tr{w') for all w, w' G W. 

Given an update structure U = (W,d, vr), we define {i-plu = {w ■ ■K{w)(ip) = true}. Kat- 
suno and Mendelzon use update structures as semantic representations of update operators. 
Given an update structure U = (W, d, vr) and sets A,BC W, Katsuno and Mendelzon de- 
fine mmu{A, B) to be the set of worlds in B that are closest to worlds in A, according to 
d. Formally, imn.u{A,B) = {w G B : Bwq G A'^w' G B d{wQ,w') -jt d{wQ,w)}. 

Theorem 6.1: (Katsuno & Mendelzon, 1991b) A belief change operator o satisfies U1-U8 
if and only if there is an update structure U = {W, tt, d) such that 

{(f o ipju = minuiMu, hPju)- 

Thus the worlds the agent believes possible after updating with tp are these worlds that are 
closest to some world considered possible before learning ^p. 

Katsuno and Mendelzon's account of update is "static" in the sense that it describes a 
single belief change. Nevertheless, there is a clear intuition that each world w' G |<^o^];7 
is the result of considering a minimal change from some world w G {(fju- However, in 
Katsuno and Mendelzon's representation, we do not keep track of the worlds that "lead to" 
the worlds in the current belief set. 

We now try to capture behavior similar to Katsuno and Mendelzon's semantics in our 
framework. We define systems where each run describes the sequence of changes, so that the 
most plausible runs, given a set of observations, correspond the worlds that define the belief 
set in Katsuno and Mendelzon's semantics. More precisely, given a sequence of observations 
ijji, . . . ,ijjn, each world in {ipoi/jiO. . .oijjn}u can be "traced" back through a series of minimal 
changes to a world in {i^Ju- In our model, each such trace corresponds to one of the most 
plausible runs, where the environment state at time m is the mth world in the trace. We 
can capture this intuition by using a family of priors with a particular form. 

We start with some preliminary definitions. Let X be a BCS, and let so,...,Sn be a 
set of environment states in I. We define [sq, . . . , Sn] as the set of runs where re(i) = 
for all < i < n. Thus, [sq, • • • , describes a set of runs that share a common prefix of 
environment states. A prior plausibility space Va = ij^-, Pla) is consistent with a distance 
measure d if the following holds: 

Pla([sO) < Pla([so, . . . , s^]) if and only if there is some j < n such that 

Sk = for ah < fc < j, s^+i / 4+1, and d{sj, Sj+i) < d{sj, s^+i). 

Intuitively, we compare events of the form [sq , • • • , Sn] using a lexicographic ordering based 
on d. Notice that this ordering focuses on the first point of difference. Runs with a smaller 
change at this point are preferred, even if later there are abnormal changes. This point is 
emphasized in the borrowed car example below. 

Pla is prefix- defined if the plausibility of an event is uniquely defined by the plausibility 
of run-prefixes that are contained in it, so that 
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Pla{U[ipo, . . . , ipm]) > Pla(7^[^o, • • • , V'm]) if and only if for all [sq, . . . , Sm] ^ 
TZlipo, iprn] - T^i^o, • • • , ^m] there is some [s'q, ■■■,s'^] C n[ipo, ifm] such 

that Pla([So, • • • , s'^]) > Pla([so, • • • , Sm])- 

Roughly speaking, this requirement states that we compare events by properties of dom- 
inance. This property is similar to one satisfied by the plausibility measures that we get 



from preference ordering using the construction of Proposition 2.2 . 

We define the set to consist of BCSs I = {TZ, vr, V) that satisfy the following four 
requirements UPD1-UPD4. UPDl says that there are only finitely many possible truth 
assignments, and that there is a one-to-one map between environment states and truth 
assignments. 

UPDl The set of propositions (of BCSl) is finite and vr is such that for 
all environment states s, s', if s 7^ s', then there is a formula G Cg such that 
s \= (p and s' \= ^f. 

UPD2-UPD4 are analogues to REV2-REV4. Like REV2, UPD2 puts constraints on 
the form of the prior, but now we consider lexicographic priors of the form described above. 

UPD2 The prior of BCS5 is prefix defined and consistent with some distance 
measure. 

Recall that REVS requires only that all truth assignments initially have nontrivial plau- 
sibility. In the case of revision, the truth assignment does not change over time, since 
we are dealing with static propositions. In the case of update, the truth assignment may 
change over time, so UPD3 requires that all consistent sequences of truth assignments have 
nontrivial plausibility. 

UPD3 li(pi G Ce, i = 0, . . . , k, are consistent formulas, then Fl{TZ[ipo, . . . , ipk]) > 
_L. 

Finally, like REV4, UPD4 requires that the agent gain no information from her obser- 
vations beyond the fact that they are true. 

UPD4 FlaiTl[ipo, . . . ,ipk+i;Oi, . . . ,0k]) > Pla(7^[■^/'0,•••,V'm+l;Ol,...,Om]) if 
and only if Pla(7^[(/?o, ^piAoi, . . . ,ipm^Om, V'm+l]) > Pla{TZ[ipo,i'i A 01, . . . , V^m A 

We remark that in the presence of REVl, UPD4 is equivalent to REV4. We might consider 
generalized versions of UPD4, where the two sequences of formulas can have arbitrary 
relative lengths; this version suffices for our purposes. We can also define an analogue 
UPD4' in the spirit of REV4', which applies only if Pl(7^[990) • • • 1 Vm+i', oi, . . . , 0^]) > _L. 

We now show that corresponds to (KM) update. Recall that Katsuno and Mendelzon 
define an update operator as mapping a pair of formulas (//, ip), where /i describes the agent's 
beliefs and ip describes the observation, to a new formula fio ip that describes the agent's 
new beliefs. However, as we discussed in Section |3|, when <I>e is finite, we can also treat o 
mapping a belief state and a formula to a new belief state. Also recall that Bel(T, Sa) is the 
agent's belief set when her local state is Sa- 
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Theorem 6.2: A belief change operator o satisfies U1-U8 if and only if there is a system 
I € such that 

Bel(I, Sa) oip = BeliZ, Sa ■ tp) 
for all epistemic states Sa and formulas ip ^ Ce- 

Proof: Roughly speaking, we show that any system in corresponds to a Katsuno and 
Mendelzon update structure. Suppose that T =G is such that the set of environment 
states is Se and the prior of BCS5 is consistent with distance function d. We define an 
update structure C/j. We then show that belief change in Z corresponds to belief change in 
Uj in the sense of Theorem |6.l| . Since Theorem ST states that any belief change operation 



defined by an update structure satisfies U1-U8, this will suffice to prove the "if" direction 
of the theorem. To prove the "only if" direction of the theorem, we show that that for any 
update structure U , there is a system T G such that Ux = U. 



See Appendix A. 2 for details. □ 



This result immediately generalizes to sequences of updates. 

Corollary 6.3: A belief change operator o satisfies U1-U8 if and only if there is a system 
Xo G such that for all tpi, . . . S Ce, we have 

Bel{l<,, Sa)o^iO ■■■o^k = Bel{Io, Sa • V'l • • • • • V'fc)- 

These results show that for update, unlike revision, the systems we consider are such that 
the belief state does determine the result of the update, i.e., if Bel(T, Sa) = Bel(T, s'^), then 
for any ip we get that Bel(I, Sa-^) = Bel(T, • </?). Roughly speaking, the reason is that the 
distance measure that determines the prior does not change over time. While this allows 
us to get an elegant representation theorem, it also causes problems for the applicability of 
update, as we shall see below. 

Note that, since the world is allowed to change, there is no problem if we update by a 
sequence ■01 , . . . , V'fc of consistent formulas such that ipi A . . . A ipk is inconsistent. There 
is no requirement that the formulas tpi, . . . ,ipk be true simultaneously. All that matters is 
that ij^i is true at time i. Also note that an update by an inconsistent formula does not pose 
a problem for our framework. It follows from postulates Ul and U2 that once the agent 
learns an inconsistent formula (i.e., false), she believes false from then on. 

How reasonable is the notion of update? As the discussion of UPD2 above suggests, it 
has a preference for deferring abnormal events. This makes it quite similar to Shoham's 
chronological ignorance (1988), and it suffers from some of the same problems. Consider 
the following story, that we call the borrowed- car example^ At time 1, the agent parks her 
car in front of her house with a full fuel tank. At time 2, she is in her house. At time 3, 
she returns outside to find the car still parked where she left it. Since the agent does not 
observe the car while she is inside the house, there is no reason for her to revise her beliefs 
regarding the car's location. Since she finds it parked at time 3, she still has no reason 
to change her beliefs. Now, what should the agent believe when, at time 4, she notices 
that the fuel tank is no longer full? The agent may want to consider a number of possible 



11. This example is based on Kautz's stolen car story (1986), and is due to Boutilier, who independently observed 
this problem [private communication, 1993]. 
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explanations for her time-4 observation, depending on what she considers to be the most 
hkely sequence(s) of events between time 1 and time 4. For example, if she has had previous 
gas leaks, then she may consider leakage to be the most plausible explanation. On the other 
hand, if her spouse also has the car keys, she may consider it possible that he used the car 
in her absence. Update, however, prefers to defer abnormalities, so it will conclude that the 
fuel must have disappeared, for inexplicable reasons, between times 3 and 4. To see this, 
note that runs where the car has been taken on a ride have an abnormality at time 2, while 
runs where the car did not move at time 2 but the fuel suddenly disappeared, have their 
first abnormality at time 4, and thus are preferred! 

Suppose wc formalize the example using propositions such as car- parked- outside, fuel- 
tank-full, etc. Let the agent's belief set at time i be //j, i = 1, . . . , 4. Notice that /xi includes 
the belief that the car is parked in front of the house with a full fuel tank. (That is, 
l~£e Ml =^ fuel-tank-full A car-parked-outside.) At time 2 the agent makes no observations 
since she is in her house, so /X2 = o t^ue = fii by U2. At time 3 the agent observes 
the car outside her house, so /is = /U2 o car-parked-outside = fii, again by U2. Finally, 
A*4 = M3 ^ ^fuel-tank-full. The observation of -^fuel-tank-full at time 4 must be explained 
by some means. In our semantics, the answer is clear. The most plausible runs are these 
where the car was parked until time 3, and somewhere between time 3 and 4 some change 
occurred. 

Is this counterintuitive conclusion an artifact of our representation? To some extent 
it is. This issue cannot be formally addressed within Katsuno and Mendelzon's semantic 
framework, since that framework docs not provide an account of sequences of changes. 
Moreover, one might argue that within out framework there might be other families of priors 
that satisfy U1-U8, which will offer alternative explanations of the surprising observation 
at time 4. Nevertheless, we claim that our semantics captures, in what we believe to 
be the most straightforward way, the intuition embedded in the Katsuno and Mendelzon's 
representation. In particular, condition UPD2, which enforces the delay of abnormal events, 
was needed in order to capture the "pointwise" nature of the update. It would be interesting 
to know whether there is a natural way of capturing update in our framework that does not 
suffer from these problems. 

Does this way of capturing update scmantically ever lead to reasonable results? Of 
course, that depends on how we interpret "reasonable" . We briefly consider one approach 
here. 

In a world w, the agent has some beliefs that are described by, say, the formula (p. These 
beliefs may or may not be correct (where we say a belief ip is correct in a world w p is true 
of w). Suppose something happens and the world changes to w' . As a result of the agent's 
observations, she has some new beliefs, described by ip'. Again, there is no reason to believe 
that (p' is correct. Indeed, it may be quite unreasonable to expect cp' to be correct, even if 
p is correct. Consider the borrowed-car example. Suppose that while the agent was sitting 
inside the house, the car was, in fact, taken for a ride. Nevertheless, the most reasonable 
belief for the agent to hold when she observes that the car is still in the parked after she 
leaves the house is that it was there all along. 

The problem here is that the information the agent obtains at times 2 and 3 is insufficient 
to determine what happened. We cannot expect all the agent's beliefs to be correct at this 
point. On the other hand, if she does obtain sufficient information about the change and 
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her beliefs were initially correct, then it seems reasonable to expect that her new beliefs will 
be correct. But what counts as sufficient information? 

We say that (/? provides sufficient information about the change from w to w' if there 
is no world w" satisfying 99 such that d{w,w") < d{w,w'). In other words, 99 is sufficient 
information if, after observing ip in world w, the agent will consider the real world (w') one 
of the most likely worlds. Note that this definition is monotonic, in that if ip is sufficient 
information about the change, then so is any formula ip that implies 99 (as long as it holds at 
w'). Moreover, this definition depends on the agent's distance function d. What constitutes 
sufficient information for one agent might not for another. We would hope that the function 
d is realistic in the sense that the worlds judged closest according to d really are the most 
likely to occur. 

We can now show that update has the property that if the agent has correct beliefs and 
receives sufficient information about a change, then she will continue to have correct beliefs. 

Theorem 6.4: Let 2 € C^. // the agent's beliefs at {r,m) are correct and 0{^r,m) provides 
sufficient information about the change from re{m) to rf>{m + 1), then the agent's beliefs at 
(r, m + 1) are correct. 

Proof: Straightforward; left to the reader. □ 

As we observed earlier, we cannot expect the agent to always have correct beliefs. Nev- 
ertheless, we might hope that if the agent does (eventually) receive sufficiently detailed 
information, then she should realize that her beliefs were incorrect. But this is precisely 
what does not happen in the borrowed-car example. Intuitively, once the agent observes 
that the fuel tank is not full, this should be sufficient information to eliminate the possi- 
bility that the car remained in the parking lot. However, it is not. Roughly speaking, this 
is because update focuses only on the current state of the world, and thus cannot go back 
and revise beliefs about the past. 

The problem here is again due to the fact that belief update is determined only by the 
agent's belief state and not her epistemic state. Thus, update can only take into account 
the agent's current beliefs and not other information, such as the sequence of observations 
that led to these beliefs. In our example, if we limit our attention to beliefs about the car's 
whereabouts and the fuel tank, then since the agent has the same belief state at time 1 
and 3, she must change her beliefs in the same manner at both times. This implies that the 
observation the fuel tank is not full at time 4 cannot be sufficient information about the 
past, since a fuel leak might be the most plausible explanation of missing fuel at time 2.I1HI 

Our discussion of update shows that update is guaranteed to be safe only in situations 
where there is always enough information to characterize the change that has occurred. 
While this may be a plausible assumption in database applications, it seems somewhat less 
reasonable in AI examples, particularly in cases involving reasoning about action.EJ 

12. In this example the usual intuition is that, given the observation that the tank is not full, the agent should 
revise her belief in some manner instead of performing update. This immediately raises the question of how 
the agent knows what the right belief change operation should be here. We return to this issue below. 

13. Similar observations were independently made by Boutilier (1996b), although his representation is quite 
different from ours. 
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Environment changes 


No change 
(Static propositions) 


All possible sequences 


Initial plausibility 


Total preorder 


Lexicographic 


Belief change 


Conditioning 


Conditioning 



Table 1: A summary of the restrictions we impose to capture revision and update. 



7. Synthesis 

In previous sections we analyzed belief revision and belief update separately. We provided 
representation theorems for both notions and discussed issues specific to each notion. In 
this section, we try to identify some common themes and points of difference. 

Katsuno and Mendelzon (1991a) focused on the following three differences between AGM 
revision and KM update: 

1. Revision deals with static propositions, while update allows propositions that are not 
static. 

2. Revision and update treat inconsistent belief states differently. Revision allows an 
agent to "recover" from an inconsistent state after observing a consistent formula. 
Update dictates that once the agent has inconsistent beliefs, she will continue to have 
inconsistent beliefs. As we noted above, it seems that revision's ability to recover from 
an inconsistent belief set leads to several technical anomalies in iterated revision. 

3. Revision considers only total preorders, while update allows partial preorders. 

Our framework suggests a different approach to categorizing the differences between 
revision and update (and other approaches to belief change): focusing on the restrictions 
that have to be added to basic BCSs to obtain systems in and C^, respectively. In 
particular, we focus on three aspects of a system: 

• How does the environment state change? 

• How does the agent form her initial beliefs? What regularities appear in the agent's 
beliefs at the initial state? 

• How does the agent change her beliefs? 

Table |l] summarizes the answers to these questions for revision and update; it highlights 
the different restrictions imposed by each. Revision puts a severe restriction on changes 
of the environment (more precisely, on how we describe the environment in the language) 
and a rather mild restriction on the agent's prior beliefs (they must form a total preorder). 
On the other hand, update allows all sequences of environment states, but requires the 
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agent's prior beliefs to have a specific form. These formal properties match the intuitive 
description of revision and update given in (Alchourron et al., 1985; Katsuno & Mcndclzon, 
1991b). However, the explicit representation of time in our framework allows us to make 
these intuitions precise. Moreover, our framework makes explicit other assumptions made 
by revision and update. For example, the lexicographic nature of update is not immediately 
evident from the presentation in (Katsuno & Mendelzon, 1991b). 

The key point to notice in this table is that belief change in both revision and update 
is done by conditioning. This observation, and the naturalness of conditioning as a notion 
of change, support our claim that conditioning should be adopted as semantic foundations 
for minimal change. 

How significant are the differences between revision and update? We claim that some 
of these differences are a result of different ways of modeling the same underlying process. 
Recall that in the introduction we noted that the restriction to static propositions is not such 
a serious limitation of belief revision, since we can always convert a dynamic proposition 
to a static one by adding timestamps. More precisely, we can replace a proposition p by a 
family of propositions p"^ that stand for is true at time m" . This makes it possible to 
use revision to reason about a changing world. We now show how revision and update can 
be related under this viewpoint. 

To make this discussion precise, we need to introduce some formal definitions. Let 
I = {n,TT,'P) be a BCS. We "statify" I into a system I* = {n*,TT*,V*) by replacing the 
underlying language with static propositions. 

Let $* = {p^ : p € ^e, fn G iV} be a set of timestamped propositions and let C* be the 
logical language based on these propositions. We can easily "timestamp" every formula in C 
We define timestamp((/7, m) recursively as follows. The base case is timestamp(p, m) = p™" 
for p G $e- For standard logical connectives, we simply apply the transformation recursively, 
for example timestamp((/? Aip) = timestamp((^, m) A timestamp(^, m). 

Next, we define the set of runs in the "statified" system. For each run r £ TZ, we 
define a r* in TZ* as follows. The environment states in r* are defined to be the whole 
sequence of environment states in r, that is, r*(m) = Vg- If ra{m) = (0(^1), . . . , oi^r,m))j we 
define Vairn) = (timestamp(o(^ 1), 1), . . . , timestamp (o(r„j), m)). We define the interpreta- 
tion IT* in the obvious way: iT*{r* ,m){p"^') = true if and only if Tr(r,m')(p) = true and 
Tr*{r* ,m){learn{ip)) = true if and only if 0(^r*,m) = V- 

Finally, we need to define the prior plausibility PI*. We define this prior to be isomorphic 
to Pla under the transformation r* r. That is, for each set of runs R* CTZ*, we define 
Pl*(i?*) = Pla({r G 7^ : r* G i?*}). 

It is clear that the two systems X and I* describe the same underlying process. Perhaps 
the most significant difference is that the environment state in a run of I* encodes the 
future of the run. This was necessary so that the environment state could determine the 
truth of all propositions of the form p"^, so as to satisfy BCSl. Without this requirement, 
we could have simply changed vr and left TZ and V unchanged. 

Because different base languages are used in I and I*, the agent has different beliefs 
in the two systems. It is easy to show that, for all if G C^, we have (X, r, m) |= Bip iff 
(I*,r*,rn) \= B (timestamp {{p,m)). However, at {r*,m) the agent also has beliefs about 
propositions that describe past and future times. Thus, the set of beliefs of the agent in X* 
can be viewed as a superset of her beliefs in X at the corresponding points. 
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The following result makes precise the relationship between X and X* in terms of the 
properties we have been considering. 

Proposition 7.1: LetX he a BCS and let X* the transformed system defined above. Then 

• X* is a BCS, that is, it satisfies BCS1-BCS5. 

• X* satisfies RE VI. 

• IfX satisfies UPD3, then X* satisfies REV3. 

• If X satisfies UPD4, then X* satisfies REV4' ■ 

Proof: Straightforward; left to the reader. □ 

Thus, if T is a BCS, so is X*. Moreover, if T G C^, then X* satisfies all but two of the 
requirements for C^. First, X* does not necessarily satisfy REV2, since the prior of systems 
in is, in general, not ranked. Second, X* satisfies REV4', the weaker version of REV4. 
The reason for this is that runs X* do not allow all sequences of possible observations. 
Remember that in the language of £*, the agent can observe the proposition (i.e., that 
p is true at time 2) at time 1. However, in the original system, the agent only observes 
properties of the current time. Thus, 0(^r*,m) involves only propositions that deal with time 
m. 

Neither of these shortcomings is serious. First, variants of AGM revision that involve 
partial orders were discussed in the literature (Katsuno & Mendelzon, 1991b; Rott, 1992). 
It is fairly straightforward to show that these can captured in our systems using BCSs that 
satisfy REVl, REVS, and REV4. Second, it is easy to add to X* runs so as to get a system 
that satisfies REV4. Moreover, we can do this is a way that does not change the agent's 
beliefs for sequences of observations that can be observed in X. Thus, the "statified" version 
of a system in displays behavior much in the spirit of belief revision. 

This result may seem somewhat surprising in light of the significant differences between 
the AGM postulates and KM postulates. In part, it shows how much is bound up in our 
choice of language. (Recall that similar issues arose in Example |5.1| .) This highlights the 
sensitivity of the postulate approach to the modeling assumptions we make. Unfortunately, 
these modeling assumptions are rarely discussed in the belief change literature. (See (Fried- 
man &: Halpern, 1998a) for a more detailed discussion of this point.) 

Table ^ emphasizes that, despite the well-known differences between revision and update, 
they can be viewed as sharing one very important feature: they both use conditioning to do 
belief change. Thus, we have a common mechanism both for understanding and extending 
them. To a certain extent, our results show that revision is more general than update, in 
the sense that we can view the statified version of any system in as performing revision 
(possibly with unranked prior) over runs. 

8. Extensions 

In the preceding sections, we introduced several assumptions that were needed to capture 
revision and update. Of course, there are other ways of capturing these notions that require 
somewhat different assumptions. Nevertheless, these assumptions give insight into the un- 
derlying choices made, either explicitly or implicitly, in the definition of revision and update. 
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In addition, thinking in terms of such restrictions makes it straightforward to extend the 
intuitions of revision and update beyond the context where they were originaUy appHed. In 
this section, we consider a number of such extensions, to ihustrate our point. 

8.1 Knowledge 

In many domains of interest, the agent knows that some sequences of observations are 
impossible. We already saw in the circuit-diagnosis problem that observing failures was 
impossible. In the context of update, we know that we cannot observe a person die and 
then be alive, despite the fact that both being dead and being alive are consistent states. 

We can easily maintain what we regard as the defining properties of revision and update, 
as discussed in the previous section: no change in the environment state and a ranked prior 
in the case of revision, and a lexicographic prior in the case of update, with belief change 
proceeding by conditioning in both cases. We simply drop REVS and replace REV4 by 
REV4' (resp., drop UPD3 and replace UPD4 and UPD4'). We remark that this change 
affects the postulates. For example, consider update. Suppose that the agent considers 
the possibility that Mr. Bond is dead. If she then observes Mr. Bond alive and well then, 
according to update, she must account for the new observation by some change from the 
worlds she previously considered possible. However, there is no transition from worlds 
in which Mr. Bond is dead that can account for the new observation. Thus, once the 
agent knows that certain transitions are impossible, some observations (e.g., observing that 
Mr. Bond is alive) require her to remove from consideration some of the worlds that she 
previously considered possible. As a consequence, postulate U8 does not hold, since the 
agent's new beliefs are not determined by a pointwise update at each of the worlds she 
previously considered possible. (Boutilier (1998) uses a related semantic framework to 
draw similar conclusions in his analysis of update.) 

8.2 Language of Beliefs 

In our analysis of revision and update, we focused on the agent's beliefs about the current 
state of the environment. Often we are also interested in how the agent changes her beliefs 
about other types of statements, such as beliefs about future states of the environment, 
beliefs about other agents' beliefs, and introspective beliefs about her own beliefs. Again, 
it is straightforward in our framework to deal with an enriched language that lets us ex- 
press such statements. For example, in (Friedman & Halpern, 1994) we examine Ramsey 
conditionals. These are formulas of the form > ■0, which can be read as saying "after 
learning (/?, the agent believes This formula can be expressed as learn{ip) =^ BiIj in the 
language C^^^ . As is well known, if belief sets include Ramsey conditionals (and not just 
prepositional formulas), then the AGM postulates become inconsistent (at least, provided 
we have at least three mutually exclusive consistent formulas in the language) (Gardenfors, 
1986). Similar inconsistency results arise when one tries to add other forms of introspective 
beliefs (Fuhrmann, 1989). In our setting, it is easy to see why the problem arises. Even 
if we allow belief sets to include nonpropositional formulas, it still seems quite clear that 
we want to distinguish the propositional formulas from formulas that talk explicitly about 
an agent's beliefs. For example, it is not clear that we should allow an observation of a 
formula such as ip > ip. What would it mean to observe such a formula? It clearly seems 
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quite different from observing a propositional formula. Nor does it make sense to extend an 
assumption such as REVl to arbitrary formulas. While it may be reasonable to restrict to 
static propositions if we are viewing these as making statements about a relatively stable 
environment, it seems far less reasonable to assume that formulas that talk about an agent's 
beliefs will be static, especially when we are trying to model belief change! 

Of course, if we allow only propositional formulas to be learned (or observed), and 
restrict REVl to propositional formulas, then it is easy to see that all of our results still 
hold, even if the full language is quite rich; we avoid the triviality result completely. 



8.3 Observations 

One of the strongest assumptions made by revision and update involves the treatment of 
observations. This assumption seems unreasonable in most domains. REV4 and UPD4 
essentially assume that the observation that the agent makes is chosen randomly among 
all formulas consistent with the current state of the world. Suppose that i-p says that the 
agent is outdoors, says that the agent is in the basement, and o\ says that the basement 
light is on. We may well have Pla('/^[v? A oi]) > Pla('7?.[V' A oi]). For example, the agent 
may hardly ever go to the basement and frequently go outdoors, but her children may often 
leave the basement light on. Nevertheless, we may also have Pla(7^[(/9; oi]) < Pla(7^[^/^; oi]), 
contradicting REV4. Indeed, it may well be impossible for the agent to observe that the 
basement light is on when she is outdoors, so that Pla(7^[(^; oi]) = _L, but this is not 
permitted according to REV4 or UPD4. 

In many domains it is useful to reason about hidden quantities that simply cannot be 



observed. For example, the event that component Cj is faulty in Example is a basic 
event in our description of the problem, yet it cannot be observed. Similarly, the event 
where a patient has a disease X or the opponent is planning to capture the queen are useful 
in reasoning about medical diagnosis and game strategy, yet are not directly observable in 
practice. Thus, the requirement that all formulas in the language can be observed seems 
quite unnatural. We note that explicitly modeling sensory input is a standard practice in 
control theory and stochastic processes (e.g., in hidden Markov chains). In these fields, 
one models the probability of an observation in various situations. Making an observation 
increases the probability of situations where that observation is likely to be observation and 
decreases the probability of situations where it is unlikely. Again, it is straightforward to 
consider a more detailed model of the observation process in our framework; see (Friedman, 
1997, Chapter 6) and (Boutilier et al., 1998). 



8.4 Actions 

Our definition of belief change systems essentially assumes that the agent is passive. The 
situation is more complex when the agent can influence the environment. The agent's choice 
of action interacts with hsr beliefs. It is clear that after performing an action, the agent 
should change her beliefs.1111 Moreover, the information content of observations depends on 
the action the agent has just performed. For example, the agent might consider hearing a 

14. Indeed, an alternative interpretation of the update postulates is that they describe how the agent should 
update her beliefs after doing the action "achieve if" (Goldszmidt & Pearl, 1996; del Val & Shoham, 1992, 
1993). However, as these works show, the update postulates are problematic under this interpretation. 
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loud noise to be surprising. However, it would be expected after the agent pulls the trigger 
of her gun. 

8.5 Summary 

This list of possible extensions is clearly not exhaustive; there are many others that we 
may want to consider. Nevertheless, these are extensions that seem to be of interest. The 
main points we want to make here are (1) it is easy to accommodate these extensions in 
our framework while still maintaining the main characteristics of revision and update, and 
(2) it is difficult to deal with such extensions if we focus on postulates. 

9. Conclusion 

We have shown how the framework introduced in (Friedman &: Halpern, 1997) can be used 
to capture belief revision and update. Modeling revision and update in the framework also 
gives us a great deal of further insight into their properties, and emphasizes the role of 
conditioning as a way of capturing minimal change. 

Of course, revision and update are but two points in a wide spectrum of possible types of 
belief change. Our ultimate goal is to use this framework to understand the whole spectrum 
better and to help us design belief change operations that overcome some of the difficulties 
we have observed with revision and update. In particular, we want belief change operations 
that can handle dynamic propositions, while still being able to revise information about the 
past. 

Our framework suggests how to construct such belief change operations. In this frame- 
work, belief change operations can be determined by choosing a plausibility measure that 
captures the agent's preferences among sequences of worlds. This is the agent's prior plau- 
sibility, and captures her initial beliefs about the relative likelihood of runs. As the agent 
receives information, she changes her beliefs using conditioning. In this paper we show that 
revision and update correspond to two specific families of priors. Clearly, however, there 
are prior plausibilities that, when conditioned on a surprising observation, allow the agent 
to revise some earlier beliefs and to assume that some change has occurred. One obvious 
problem is that, even if there are only two possible states, there are uncountably many 
possible runs. How can an agent describe a prior plausibility over such a complex space? 

One approach to doing this is based on intuition from the probabilistic settings. In 
these settings, the standard solution to this problem is to assume that state transitions are 
independent of when they occur, that is, that the probability of the system going from state 
s to state s' is independent of the sequence of transitions that brought the system to state 
s. This Markov assumption significantly reduces the complexity of the problem. All that 
is necessary is to describe the probability of state transitions. In (Friedman & Halpern, 
1996; Friedman, 1997) we define a notion of plausibilistic independence, and show how to 
describe priors that satisfy the Markov assumption and the consequences for belief change. 
See also (Boutilier, 1998; Boutilier et al., 1998) for recent proposals along these lines. 

Whether or not this particular approach turns out to be a useful one, it is clear that 
these are the types of questions we should be asking. As these works show, our framework 
provides a useful basis for answering them. 
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Finally, we note that our approach is quite different from the traditional approach to 
belief change (Alchourron et al., 1985; Gardenfors, 1988; Katsuno &: Mendelzon, 1991a). 
Traditionally, belief change was viewed as an abstract process. Our framework, on the other 
hand, models the agent and the environment she is situated in, and how both change in time. 
This allows us to model concrete agents in concrete settings (for example, diagnostic systems 
are analyzed in (Friedman &: Halpern, 1997) and throughout this paper), and to reason 
about the beliefs and knowledge of such agents. We can then investigate what plausibility 
ordering induces beliefs that match our intuitions. By gaining a better understanding of 
such concrete situations, we can better investigate more abstract notions of belief change. 
More generally, we believe that, when studying belief change, it is important to specify the 
underlying ontology: that is, exactly what scenario underlies the belief-change process. We 
have specified one such scenario here. While others are certainly possible, we view it as a 
defect in the literature on belief change that the underlying scenario is so rarely discussed. 
The framework we have introduced here provides a way of making formal what the scenario 
is. (See (Friedman &: Halpern, 1998a) for further discussion of this issue.) 
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Appendix A. Proofs 
A.l Proofs for Section ^ 



We start with the proof of Theorems and p.3| . To do this, we need some preliminary 
definitions and lemmas. Figure 1 shows the general outline of the intermediate represen- 
tations we use in these proofs. Roughly speaking, we show how to map from a revision 
operator o and a consistent belief set K to a. ranking, and similarly how to map from a 
ranking to an AGM revision operator. These rankings correspond, in a direct way, to priors 
in systems in C^, and thus have close connection to the beliefs of the agent in various states. 

These mapping between AGM revision operators and rankings are related to the repre- 
sentation theorems of Boutiher (1994b), Grove (1988), and Katsuno and Mendelzon (1991a). 
However, the exact details of our representations are different than those of Boutilier, Grove, 
and Katsuno and Mendelzon. Thus, for completeness we provide the full proofs here. 



151 



Friedman & Halpern 



AGM 
Revision 



Lemma A.l 



Set of 
Defaults 



Lemma A. 2 



Lemma A. 3 




Lemma A. 4 



Ranked 
Structure 



\1 



Characteristic 
Structure 

PLr 



Figure 1: Schematic description of the entities and lemmas involved in the proof of Theo- 
rems and 5.3. 



We start with the mapping from revision operator applied to a specific belief set to a 
ranking. As an intermediate step we construct a set of defaults as follows. We then will use 
the results from (Friedman &: Halpern, 1998b) to construct a ranked plausibility structure 
that satisfies these defaults. 

Lemma A.l: Let o be an AGM revision operator, let K Q Ce be a consistent belief set, 
and let 

Then the following is true: 

(a) A(^a,K) closed under the rules of system P, 

(b) if — y false ^(o,_ft:) for all consistent ip G Ce, and 

(c) A(o satisfies rational monotonicity; that is, if ip — ^tp £ A(o,_ft:) (^"i^d (p — y^(, A(o 7^), 
then ip A ^^^p G Af^^^j^y 

Proof: We start with part (a): 

LLE Assume that hc^ ^p = (p' and that ip — G A(o,_ft'). Thus, ip £ K o <p. From R5, it 
follows that tp £ K o ip', and thus ip' — ^^p G A^^ 

RW Assume that l-£^ ip ^ ip' and that 99 — >ip G A(^o,k)- Thus, ip £ K oip. Since K o ip is a 
belief set, it is closed under logical consequence. In particular, ip' £ K o <p, and hence 
ip^ip' G A(o,i^). 

REF By R2, ip £ K o ip, and thus, 99 — >pi G A^^, j^). 
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AND Assume that tp — ^il^i^ip — *-V'2 ^ ^{o,k)- Thus, '4'i,'4'2 G K o ip. Since K o ip \s a, behef 
set, ipi Aip2 ^ K o ip. Thus, p^ipi Aip2 ^ '^{o,K)- 

OR Assume that pi — ^tp,p2 — S ^{o,k)- There are two cases. U K o {pi V P2) is 
inconsistent, then ip G K o {pi V 1P2) and thus tpi V p}2 — & ^{o,K)- K o {p?i V P2) is 
consistent, then, by R2, p\\J p2 £ K o {pi V ^2)- Thus, we cannot have both -^pi and 
-1(^2 in K o (pi V 992)- Without loss of generahty, assume that -^pi ^ K o (^pi \/ P2). 
Using R7 and R8, we get that K o {{p^ V P2) A pi) = Cl{K o {pi V P2) U {pi}). 
Using R6, we get that K o ((pi V P2) A pi) = K o pi. Thus, we conclude that 
K o pi = Cl(K o (pi V P2) U {pi})- Since pi — ^4' ^ ^(o,x)) we have that tp € K o pi. 
Thus, we get that pi ^ ip & Ko(pi \/p2)- If ^P2 Ko(pi yp2), by similar arguments 
we get that p2 ^ ip & Ko(pi \/p2)- This implies that (pi V P2) =^ ip & Ko(pi \/p2), 
and thus ip ^ K o (pi y p2)- On the other hand, if -^p2 € K o (pi V P2), then, since 
piV P2 € K o (pi V P2), we get that pi & K o (pi V P2), and thus ip ^ K o (pi V p2)- 

CM Assume that p — ^ipi,p — ^tl'2 £ ^{o,k)- K o p is inconsistent, then using R5 we get 
that p is inconsistent. Thus, pf\tpi is inconsistent, so -02 S K o(p /\'il)i). Now assume 
that K o p \s consistent. Since p — ^tpi, we have that -01 ^ K o p. Since K o p \s 
consistent, we get that -i-^i ^ K op. Applying R8, we get that KopQKo(p/\ -ipi). 
Since p — ^1^2 & ^(o,_ft:)) we have that ip2 ^ K o p. Thus, 02 ^ K o (p /\ ipi). This 
implies that (p A -^i) — ^02 £ ^(o.i^')- 

We now prove part (b). Let € £e be a consistent formula. Then, using R5, we get 
that K o p \s consistent. Thus, p — > false ^ A^q^^-j. 

Finally we prove part (c). Assume that p — ^ijj € Ai-o^/^-), and p A ^ — yp ^ lS.(^o,K)- Since 
(/J — ^"0 G A(o we have that ip € K o p. Now if -1^ ^ X o then, using R8, we have that 
Cl(K op[j{^}) C K o (p A^,). This implies that tp € -R'o((^Ai^). However, since we assumed 
that p A ^ — ^0 ^ A(o^^), we have that ip ^ K o (p f\ £P)] thus, we get a contradiction. We 
conclude that ^ K o p. Thus, p — G A(o x)- ^ 

We now use this result to show that there exists a plausibility structure that corresponds 
to o applied to K. 

Lemma A. 2: Let o he an AGM revision operator, and let K Q Ce be a consistent belief set. 
Then there is a plausibility structure PL = (W, PI, vr) such that PI is ranked, PL \= p — >-'p if 
and only if ip ^ K o p, and Pld^j]) > _L for all hc^- consistent formulas p € Ce- 

Proof: We use the basic techniques described in the proof of (Friedman &: Halpern, 1998b, 
Theorem 8.2). Let A(^o,k) the set of defaults defined by Lemma |A.1| . We now construct 
a plausibility space PL' = (W,FI',tt) such that PL' \= p — ^ip if and only if p — ^ip G A(^o,k)- 
We define PL' as follows: 

• W = {wy : F C is a maximal l-£^ -consistent set}, 

• 'k(wv)(p) = true if p G and 

. VM(Ip\) > P1'(I01) if and only if (p V ij)^p G A(„,;^). 

Using (Friedman &; Halpern, 1998b, Lemma 4.1), we get that PL' \= p — ^^p if and only if 
p — *tp G A(o From Lemma |A.1| (c) and and results of (Friedman & Halpern, 1998b), it 
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follows that there is a ranked plausibility measure PI that is default-isomorphic to Pi', that 
is (W,Pl,7r) satisfies precisely the same defaults as (VF,Pl',7r). Let PL = (W^, PI, vr). 

Since PL is default-isomorphic to PL', we have that PL \= (p — if and only if ip — G 



A(^a,K)- Moreover, using Lemma |A.1| , we have that ip — ^ ^{o,k) if s-^id only ii tp ^ K o ip. 
Thus, PL \= ip — ^ij: if and only if -0 G Koip. Finally, let iphe a -consistent formula. From 
Lemma [A.l| (b), we get that (p — ^ false ^ A(o X)- Since A(o,k) is closed under the rules of 
system P, we conclude that {ip y false) — ^false ^ A(o x)- Thus, Pl'(|(^]) ^ _L = Pl'([/a/se]), 
and thus Pl'([(/9]) > _L. Since PI is default-isomorphic to PI', we conclude that Pl(|(/?]) > _L. 
□ 



We now prove the converse to Lemma A.2| . 



Lemma A. 3: Let PL = (1^, PI, vr) be a ranked plausibility structure such that ■7t{w) is ^Ce' 
consistent for all worlds w, and PL ^ ip — ^ false for all \- c^- consistent formulas ip G Ce; 
let K = {ip ^ Ce '■ PL \= true — >ip}- Then there is an AGM revision operator o such that 
ij) ^ K o ip if and only if PL \= ip — 

Proof: Let o be some belief change operation such that K o ip = {ip : PL \= ip — Since 
this requirement constrains only the result of applying o to K, we can assume without loss 
of generality that o satisfies the AGM postulates when applied to belief sets other than K. 
Thus, we need prove only that o satisfies the AGM postulates for revision applied to K. 
(Note that the proofs for R3 and R4 follow from the proofs for R7 and R8, respectively.) 



Rl Since PL is qualitative, we have that {ip : PL \= ip — ^ip} is a belief set, that is, closed 
under logical consequences. 

R2 Axiom CI implies that PL \= ip — ^ip. Thus, ip ^ K o ip. 

R5 By our assumptions, if ip is h^^-consistent, then Pl(|(/?]) > _L, and thus PL ^ ip — >false. 
On the other hand, if ip is not l-£g-consistent, then {ipj = 0, and thus Pldv?]) = _L. 
We conclude that Pl([(^]) = _L if and only if ^ip. This implies that PL \= ip — ^ false 
if and only if hc^ Thus, K o ip = Cl{false) if and only if -k/?. 

R6 Assume that ip 44> ip' . Then, by our assumption, 'K{w)[ip) = 'K{w){ip'). Thus, 
Iv? A V'] = [v?' A for all formulas tp & Ce- We conclude that PL \= ip — ^ip if and only 
if PL \= ip' — ^ip. This implies that K o ip = K o ip' . 

R7 There are two cases: either ¥\{{ip A = _L or Pl(|v9 A -01) > -L. If Pl(b A ipf) = 
_L, then (/9 A ■0 is inconsistent. According to R2, we have that ip € K o ip. Thus, 
ip Alp (z Cl{K o ip\J {ip}). This implies that Cl{K o ipU {ip}) contains false, and thus 
Ko{ipAip)(l Cl{Kop\j{ip}). If Pl(|v9 At/-]) > ±, let i e K o{ip Aip). We now show 
that i G Cl{K oip\J {ip}). This will show that K o {ip Aip) <Z Cl{K oipU {ip}). Since 
^ e K o {ip Alp), we get that PL \= {ip A ip)^^. Since Pl([(^ A ipj) > _L, we get that 
Pl{lipAipACj) > Pl{lipAipA^Cj)- ThenwehavethatPl([v9A(V' ^ 61) > P1(I<^A^(V' 
£,))}), since {ip A ip A ^) ^ {p A {ip ^ 6) and {ip A -^{ip ^ £,)) ^ {p Aip A ^^). This 
also implies that P1(M) > -L. Thus, PL |= p^{ip ^ 0- So, {ip ^ ^ K o p, and 
thus^ G Cl{K opU{ip}). 

R8 Assume that ^ip ^ K op. Let ^ G Cl{K op\J {ip}). We now show that ^ G K o{p Aip). 
This win show that Cl{K o p\J {ip}) C Ko{pAip). Let A = {pA^ip}, B = {pAipA^}, 
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and C = A -0 A -i^]. It is easy to verify that these sets are pairwise disjoint. Since 
ipA{'ip^£,) = (99 A -10) ViipAipA^,) and {ipA^{iJj =^ ^)) = {(pAijj A -i^), we conclude 
that y A{ip ^ ^)} = AU B, and {ip A 01 = C- Since ^ G Cl{K oipU 

we have that (V" ^ ^ K o tp. This means that PL \= p>^{il^ =^0- Thus, either 
Pl(|99l) = ± or V\{AyjB) > P1(C). If P1(M) = -L, then according to Al, we get that 
Pl(|(^ A ipj) = ±. Thus. PL \= (ip A i/j) — vacuously, and E K o (^tp A ip) as desired. 

Now assume that Pl{A L) B) > P1(C). Since PI is ranked, it satisfies A4' and A5'. 
According to A5', wc get that cither Pl{A) > P1(C) or Pl{B) > P1(C). Assume that 
Pl(^) > P1(C) and Pl(i3) :^ P1(C). Then, using A4', we get that Pl(^) > P1(B). 
Applying A2, we get that Pl{A) > Fl{B U C). However since A = {(p A -^ipj and 
B L) C = Ip A this implies that ^tp E K o p^ which contradicts our assumption. 
Thus, we conclude that Pl{B) > P1(C). Since B = {p Aip A^j and C = {p Aip A^^j, 
we get that PL \= {p A ip)^^, and thus ^ e K o {p A^|J). 

R3 and R4 Our definition of o implies that K o true = K. According to R6, we have that 
K o (true Ap) = K op. Combining these two facts, we get that R3 and R4 are special 
cases of R7 and R8, respectively. 

□ 

These results show how to map between ranked plausibility structures and AGM revision 
operators. Wc now relate systems in and ranked plausibility structures. Let I = 
(7^,7^,P) G C^. Recall that REV2 requires that the prior of X be a ranking. Thus, we 
can construct a ranked plausibility structure where worlds are runs in TZ. We define the 
characteristic structure of X to be PLj = (7?., PIq, ttpi^-), where Pla is the agent's prior over 
runs and '7^pij{r){p) = 7r(r, 0){p) for all p G $e- Note that Iv^IpLj = TZ[p]- 

We now use PLx to describe the beliefs of the agent in each local state. 

Lemma A. 4: Let I G and let Sa = (oi, . . . ,Om)- Then p G Bel(2, Sa) if and only if 
PLj \= (Aril O'l) — ^p- (By convention, if m = 0, we take (Aiii Oj) to be true. J 

Proof: Let T E and let Sa = {oi, ■ ■ ■ , Om)- There are two cases: either Sa is a local state 
in Z, or it is not. 

If Sa is a local state in T, suppose that ra{m) = Sa- Note that p G Bel(T, Sa) if and 
only if Pl(r,m)(M(r,m)) > Pl(r,m) (hV^l (r,m))- Recall that, according to the definition of 
conditioning, Pl(j.,„)(-) is isomorphic to Pla(-|7^[-; oi, . . . , Om]). Thus, Pl(r,m)(M(r,m)) > 
'P\r,m){h'A{r,m)) if and Only if Pla(7^[93] I n[;oi,...,Om]) > PlaCR-hp] I 'R-[-;oi,...,Om])- 
Using CI, this is true if and only if Fla{Tl[p; 01, ... , Om]) > Pla(^[~'</'; Oi, . . . , Om])- Using 
REV4, this is true if and only if Pla(7^[(/? A AI=i o^]) > Plain[-^p A AELi Oi]). We get that 
p G Bel(X, Sa) if and only if Pla{H[p A A7ii 0,,]) > Pl„(7^[-.(^ A Aj'ii oj). This implies that 
p G Bel(I, Sa) if and only if PLj \= (A™ 1 Oi)^p. 

If Sa is not a local state inT, then ??.[•; oi, . . . , Om] = 0, and by definition Pla(7^[-; oi, . . . , Om]) = 
_L. Using CI and REV4, wc get that PX„(7^[A^=l o,]) = -L, and thus PLj \= {K-Uo,i)^p 
for all p G Ce- Since Sa is not a local state in X, by definition Bel(X, Sa) = C^- Hence, we 
can conclude that p G Bel(I, Sa) if and only if PLj \= (Alii Oi) — ^p. □ 

We now show that given a ranked plausibility structure PL we can construct a system 
whose characteristic structure is default-isomorphic to PL. 
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Lemma A. 5: Let PLk = {Wk^^^k^t^k) be a plausibility space that satisfies the conditions 



of Lemma A. 5 . Then there is a system 2 € such that PLj = PLk- 



Proof: Let PLk = (IVk, Pl_ft:, vr/^) be a plausibility space that satisfies the conditions of 



Lemma |A.3| . For each world w G Wk and sequence of observations 01,02,..., let T-^'Oi'Oa,--- 
be the run defined so that rf'°^'"^''"{m) = w and r^'°i'°2''"(m) = (oi, . . . ,Om) for all m. Let 
TZ = ^j-w,oi,02,--- ■ Trk{w){oi) = true for all i}. Define vr so that 7r(r, m)(p) = VTii- (rg (m) ) (p) 
for p G and so that 7r{r,m){learn{ip)) = true if ot^r.m) = V fo^ V ^ ^e- Finally, define 
the prior plausibility Pl^ so that Pla(i?) = V\k{{w : 3r G R{w = re(0))}. It is easy to check 
that this definition implies that Pla(7^[v9]) = Plj<-([(/?]pLjy ). Thus, PLj = PLk- Since Plj^- 
is a ranking, Pl^ is also a ranking and thus qualitative. 

We now verify that the resulting interpreted system is indeed in C^. It is easy to 
check that Z is a belief change system; that is, it satisfies BCS1-BCS5. The construction 
is such that re(m) = 7'e(0) for all runs r and times m. Thus, I satisfies REVl. Since 



the prior Pl^ is a ranking, this system also satisfies REV2. Lemma A.2| implies that if (p 



is a consistent formula, then Pli^dc^Jpi^^) > _L. This implies that Pla(7^[<^]) > -L, and 
thus the system satisfies REV3. Finally, it is easy to show that Fla{TZ[ip; oi , . . . , Om]) = 
Fla{'R[(p A oi A ... A Dm]) = Pli^([93 A oi A ... A OmjpLK)- Thus, the system satisfies REV4. 
□ 



We are finally ready to prove Theorem 5.2 



Theorem |5.2| : Let o be an AGM revision operator and let K (1 Ce be a consistent belief 
set. Then there is a system T(o,k) ^ such that Bel{X{^a,K)^ ()) = K and 

Bel(I(^o,K), {))°'P = Bel{l(o,K), {^)) 

for all ip ^ Ce- 

Proof: Let o be an AGM revision operator and let if C i2g be a consistent belief set. By 
Lemmas |A.2| and |A.5| , there is a system T(o,k) = {'^{o,k)7'^{o,k)iT^{o,k)) ^ such that 
PLj^^ 1= (f — ^ip if and only if ijj ^ K o ip. Our construction is such that ^ G -ftT o if and 
only if PLj^^ j^.^ \= if — Using Lemma |A.4| , we get that PLj^^ \= (f — if and only if 
tp G Bel{Ii^o,K), i^))- Thus, K o ip = Bel(X(o,K), (</'))• 

Finally, we show Bel(X(o ()) = K. We start by showing that Kotrue = K. Using R3, 
we get that Kotrue C Cl{KVJ {true}) = K. Since K is consistent, by R4, Cl{Kyj {true}) C 
K o true. Thus, K o true = K. By Lemma |A.4| , we have that Bel(Z, ()) = Bel(X, {true)). 
Since Bel(X, (true)) = K o true, we conclude that Bel(Z(o j^), ()) = K. n 



We next prove Theorem 5.3 



Theorem |5.3| : Let 2 be a system in C^. Then there is an AGM revision operator oj such 
that 

Bel{2, {))oj^ = Bel{2, {^)) 

for all Lf ^ Ce. 



156 



Modeling Belief in Dynamic Systems. Part II. 



Proof: Let T = {TZ, vr, V) be a system in C^. It is easy to verify that PLj satisfies the 
conditions of Lemma [A.3| with K = Bel(Z, ()). This lemma imphes that there is a revision 
operator oj such that ip G K oj ip ii and only if PLj \= '-p — Using Lemma [A.4| , we have 
that G Bel(X, (99)) if and only if Plj |= c/p— >-V'. Thus, we have that K ox'p = Bel(T, (c/j)) 
for all formulas p. □ 



Theorem 5.4: Let X he a system in and Sa = {oi, . . . , Om) be a local state in 2. Then 



there is an AGM revision operator oj^sa such that 

Bel{I, Sa) oj^sa V = Bel{I, Sa ■ (f) 
for all formulas (p (z Ce such that oi A . . . Om A 99 is consistent. 



Proof: The structure of the proof is similar to that of Theorem 5.2. As in that proof. 



we construct a ranked plausibility structure and use Lemma A. 3 to find an AGM revision 



operator. The main difference is that after observing tpi, . . . ,ipk, some events are considered 



impossible. Lemma A. 3, however, requires that all possible formulas are assigned a positive 
plausibility. We overcome this problem by assigning a "fictional" positive plausibility to all 
non-empty events that are ruled out by the previous observations. 

We proceed as follows. Let do be a new plausibility value that is less plausible than 
all positive plausibilities in Pl^; that is, if Pla(^) > -L, then Pl(j(74) > do. Let X = 
{'R,'rT,V) € C^; let Sa = (oi, . . . ,Om)- We define PL = (7^, PI, vrp^^.), where PI is such that 
Pl([(^]) = max(P\a{Tl[(p A Oi]),do) for all consistent formulas if. This definition implies 
that if 99 is consistent with Ai^i Oj, then P1(|(/j]pi,) = Pla{Tl[ipi A AilLi Oi])- 

We now prove that if (p is consistent with AI^i Oj, then PL \= Lp — ^■0 if and only if 
PL^^{p^^r=loi)^'P. 

For the "if" part, assume that PLx |= (v^AAi^i Oj) — ^V- Since p) is consistent with Ai^i Oi 
it follows, from REV3, that V\a{n\p A {Kt=\ o^\)) > ±. Thus, Pla{n[{ip A [AZi Oi)) A ^]) > 
Fla{TZ[{p A (AiLi Oi)) A ^ip]) > _L. Thus, p} A ip is consistent with Ai^i Oj- This implies 
that Pl(Iv9 A ^1) = Fla{n[{p A {AT=iOi)) AiP]> max(do, Pla(7^[((^ A (AI^i o.)) A -^]) = 
Pl{lip A -^i/jj). We conclude that PL [= ip^tp. 

For the "only if" part, assume that PLj ^ (ip A {AiLiOi))^ip. This implies that 
Flainiip A {AT=iOi)) A V]) PUm^P A (A^^lO^)) A -V])- Since PL is a ranking, it 
follows that Flain[{ip A (A™ 1 Oi))V']) < PUmi^ A (A^ii o^)) A -V])- Since ± < Pla{n[ip A 
{AT=i o^)]) = max(Pl„(7^[(<^ A (A^i a)) A V]), Pla(7^[(</^ A (A™i o^)) A -V])), we have that 
Pla{n[{p A {AT=i Oi)) A ^V]) > ^- We conclude that Pl(|(^ A ^^1) > P^lv A Vl)- Thus, 
PL ^ (^^V- 

It is easy to verify that PL is ranked, and satisfies the requirements of Lemma |A.3| . Thus, 
there exists a revision operator oj ,5^ such that tp ^ K oj^g^ (p if and only if PL \= pi — >ip, 
where K = {(p : PL \= true — *-(^}. Moreover, since for all (p consistent with AE^i Oi we have 



thatPL 1= p) — ^ip if and only if PLj \= [ip A (Ai^i Oi)) — ^ip, then, from Lemma A. 4 , it follows 
that K = Bel(X, Sa) and that if ip is consistent with AE^i Oi, then PL \= p> — ^ip if and only 
if G Bel(X, Sa- p). □ 

Theorem |5.5| : Let Z he a system in whose local states are £c^ ■ There is a function 
Belj that maps epistemic states to belief states such that 
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• if Sa is a local state of the agent in I, then Bel{I,Sa) = Belx{sa), and 

• {o,Belx) satisfies Rl' -R^ . 

Proof: As we said earlier, roughly speaking, we define Belj(sa) = Bel(X, Sa) when Sa is a 
local state in X. If is not in I, then we set Belx(,Sa) = Bel(X, s'), where s' is the longest 
consistent suffix of Sa- We now make this definition precise, and show that the resulting 
Belx satisfies Rl'-R8'. 

We proceed as follows. We define a function /(•) that maps sequences of observations 
to suffixes as follows: 



/((Oi, . . .,0m)) 



if m = 0, 

{false) if m > and Om is inconsistent, 

(ofc, . . . , Om) otherwise, with k < m the minimal index 

S. t. \/c, -'(Ofc A ... A Cm)- 



Aside from the special case where Om is inconsistent, we simply choose the longest suffix of 
Sa that is still consistent. We define Belj(sa) = Bel(X, /(sq)). Clearly, if Sa is a local state 
in I, then f{sa) = Sa, so Belj(sa) = Bel(T, Sa). 

We now have to show that (o,Beli) satisfies Rl'-R8'. The proof outline is as follows. 
Given a particular state Sa, we construct a ranked plausibility structure that corresponds, 
in the sense of Lemma A. 2 , to belief change from Sa- We then use Lemma A.3| to show that 



belief changes from Sa satisfies the AGM postulates, i.e., R1-R8. Since this is true from 
any Sa, we get that Belj satisfies Rl'-R8'. 

Let Sa = (oi,...,Om)- We define a ranked plausibility space that has the following 
structure. The most plausible events are the ones consistent with oi A . . . A Om- They are 
ordered according to the prior ranking conditioned on oi A . . . A • The next tier of events 
are those that are inconsistent with oi A . . . A Om but are consistent 02 A . . . A Om- Again, 
these are ordered according to the prior ranking conditioned on 02 A . . . A Om- We continue 
this way; the last tier consists of all events that are inconsistent with Om- 

Formally, let PL = (7^, PI, ttpl^), where PI is such that P1(M) > P1(M) if PlaC7^b A 
{AiLk Oi])) > Pla('7^[V' A (Ai^k Oi])) where /c < m + 1 is the greatest integer such that for all 
j < k, ip and '0 are both inconsistent with AiLj Oi. It is easy to see that PL is ranked, and 
that if (fi is consistent, then Pl(|(/9]) > _L. 

Let (f € Ce- We now show that PL \= (p — if and only \i tp ^ Belj(,Sa -99). If is 
inconsistent, then PL \= (p — ^tp for all ip. Moreover, since 'p is inconsistent, f{sa-^) = (false), 
and thus Beli(sa • ip) = Ce- We conclude that ip — ^ip if and only ip & Beli(sa ■ (p). If (/? is 
consistent, then let k < m+1 be the greatest integer such that for all j < k, cp is inconsistent 



with Ai^j Oi- It is easy to verify that f{sa-'p) = {ok, ■ ■ ■ , Om, 'p)- From Lemma A. 4 , it follows 
that i; G Belj(sa • if) = Bel(T, {ok, . . . , o^, ip)) if and only if Pla(7^[((^ A {AT=k Oi)) A tp]) > 
PlailZliip A (Ai^fc Oi)) A -'V'])- We now show that this is the case if and only if PL \= ip^ip. 
Suppose that PLa{TZ[{ip A ^{AT=k Oi)) A ip]) > PLa{n[{ip A (AZk Oi)) A -^ip]). Then, clearly, 
PlailZliip A {AiLk Oi)) A tp]) > -L, and thus ip Aip is consistent with Ok, ■ ■ ■ , Om- Since both 
ip Alp and ip A -^ip are inconsistent with Oj, . . . ,Om for all j < k, we have that Pl([(/7 A ^]) > 
Plilif A -V'l). On other hand, if P\a{n[{f A {AT=k Oi)) ^^]) > PUm^ A (A^^^ o,)) A -V]), 
then since Pl^ is a ranking PLa{n[{ip A {AT=kOi)) A V]) < PLa{n[{^ A {AT=kOi)) A -V])- 
Moreover, since ip is consistent with o,t A . . . A Om, we have that P\a{TZ[ip A (AiLk Oi)]) > -L. 
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This implies that Pla(7^[((/J A (Allfc Oi)) A ^V]) > -L and thus Pl(|(/? A VI) < ^Klf A 
We conclude that PL \= (p — if and only if -0 G Belj(sa • v)- 

By Lemma [A.3| , there is a revision operator o^^ that satisfies R1-R8 such that ijj & KoLp 
if and only if PL \= ip — ^ij:. It is not hard to check that this implies that the change from 
Belj(sa) to Belj(sa • tp) satisfies Rl'-R8'. □ 



Proposition 5.6: Let T he a system in whose local states are £c^- There is a function 



Belx that maps epistemic states to belief states such that 

• if Sa is a local state of the agent inZ, then Bel{I,Sa) = Belx{sa), cmd 

• {o,Belx) satisfies Rf -R9' . 

Proof: As we said in the main text, we show that the function Belj defined in the proof of 
Theorem |5^ satisfies R9'. Let Sa = (oi, . . . , Om), and let ip,'ip & Ce be formulas such that 
Vce ^ V')- Since ip is consistent with tp, we get that f{sa ■ (p ■ tp) = {ok, • • • , Om, P>, V')? 
where k <m\s the least integer such that p f\tp \s consistent with o^, ■ ■ ■ ,0m- For the same 



reason, we get that f{sa-^/\ip) = {o^, ■ ■ ■ ,Om, P ^ tp)- Using Lemma we immediately 
get that Bel(T, (ofc, . . . , Om, p, V')) = Bel(T, {ok, • • • , Om, P A ip)). Thus, we conclude that 
Belj(sa ■ ^-ip) = Beli(sa ■ p Aip). □ 



Theorem 5.7: Given a function Belc^ mapping epistemic states in belief sets over 

Ce such that Belc^{{)) is consistent and {Belc^, o) satisfies Rl' , there is a system! € 
whose local states are in such that Belc^[sa) = Bel(I, Sa) for each local state Sa in I. 

Proof: We show that Bel(T, Sa) = Bel£^(sa) for local states Sa in 2, where I is the system 
guaranteed to exist by Theorem [s]^ such that Bel(X, ()) = Bel£^(()) and Bel{2,{p)) = 
Belc^iip)) for all p G Ce- We prove this by induction on the length m of Sa- For 
m < 1, this is true by our choice of I. For the induction case, let Sa = (oi,...,Om) 
be a local state in 2. Thus,, oi A . . . A Om is consistent. From R9', it follows that 
Bel£^((oi, . . . ,0m)) = Bel£^((oi, . . .,Om-2,Om-i A Om))- Using the induction hypothesis, 
we have that Belc^{{oi, . . . ,Om-2,Om-i ^ Om)) = Bel(2:, (oi, . . . , 0^-2, Om-i AOm)). Using 



Lemma |A.4 we get that Bel(I, (oi, . . . , 0^-2, o.m_i A Om)) = Bel(X, (oi, . . . , Om))- Thus, we 



conclude that Bel£g((oi, . . . , Om)) = Bel(Z, (oi, . . . , Om))- □ 



A. 2 Proofs for Section ^ 

In this section we prove Theorem 6^ . We now show that any system in corresponds to 
an update structure. Suppose that T = {TZ, vr, V) € is such that the set of environment 
states is Sg and the prior of BCS5 is consistent with distance function d. Define an update 
structure Uj = {Se,TTe,d), where for p G TTe{se){p) = TT{{se, Sa)){p) for some choice of 
Sa- By BCSl, the choice of Sa does not matter. It is easy to see that UPDl ensures that 
Se and vTe satisfy the requirements of the definition of update structures. We want to show 



that belief change in I corresponds to belief change in Uj in the sense of Theorem 6.1 



Since Theorem |6.l| states that any belief change operation defined by an update structure 
satisfies U1-U8, this will suffice to prove the "if" direction of Theorem |6.2|. To prove the 
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"only if" direction of Theorem 3.2, we show that that for any update structure U , there is 
a system Z ^ such that Uj = U. 

We start with preUminary definitions and lemmas for the "if" direction of Theorem |6.2| . 
Let Sa = {oi, ... ,0m)- We define States{I, Sa) = {s G 5e : s |= ^ for all ^ G Bel(X, Sa)}- 
Clearly, if ip is such that Bel(Z, Sq) = Cl{(p), then States{I, Sa) = {ipjux- To show that 
belief change in X corresponds to belief change in Uj we have to show that 

States{I, Sa-i)) = minuj: (States {I, Sa), lipjuj)- 

This is proved in Lemma |A.8| . To prove this lemma, we need some preliminary lemmas. 

Lemma A. 6: Let 2 € C^, and let Sa = (oi, . . . , Om)- Then (p € BeliZ, Sa) if and only if 
(X, r, 0) 1= (Ooi A ... A 0"^Om) — ^0"^V for some run r in IZ. 



Proof: The proof of this lemma is analogous to the proof of Lemma A. 4, using UPD3 and 



UPD4 instead of REVS and REV4. We do not repeat the argument here. □ 

We now provide an alternative characterization of States{I, Sa) in terms of the agent's 
prior on run-prefixes. 

Lemma A. 7: Let X € and let Sa = {oi, . . . , 0^)- Then Sm G States{2, Sa) if and only if 
there is a sequence of states [sq, • • • , Sm] ^ TZ[true, oi, . . . , Om] such that Pla([so, • • • , -Sm]) 

Pla(7^[^rue, Oi,...,Om] - [sq, . . . , Sm])- 

Proof: For the "if" direction, assume that there is a sequence SQ,...,Sm such that 
[so,...,Sm] ^ TZ[true,oi,. . . ,Om], and Pla([so, . . . , s^]) ^ FlaiTl[true,oi, . . . ,Om] - 

[Sq, . . . , Sm 

]). By way of contradiction, assume that Sm States {I, m). Thus, there is a for- 
mula ^ € Bel(X, m) such that Sm |= From Lemma [A.6| it follows that since ^ G Bel(X, Sq) , 
(X, r, 0) 1= (0^1 A ... A 0™0m) — ^■O™^ foi' some run r in TZ. From the definition of condition- 
ing it follows that PlQ(7^[iree, oi, . . . ,Om-i,Om A ^]) > Pla(7^[irae, oi, . . . ,Om_i,Om A -.,^]). 
Since Sm \= we get that [so,...,Sm] ^ ^[^^e, oi, . . . , Om_i, A -i^] and that 
TZ[true, oi, . . . , Om_i, Om, A ^] C T^ftrwe, oi, . . . , Om] — [so, ■ ■ ■ , Sm]- From Al, it follows that 
Pla{[so,...,Sm]) < P\a(n[true , Oi, . . . , Om] ~ [•So 5 • • • ) 'Sm])j which contradicts our starting 
assumption. We conclude that Sm £ States(I, Sa). 

For the "only if" direction, assume that Sm £ States{I, a). Since Se is finite and TTg 
assigns a different truth assignment to each state in Se, there is a formula ^ € £e that 
characterizes s^; that is, s |= ^ if and only if s = Sm- Since Sm G States{I, Sa), we have that 

Bel(X,Sa)- Using Lemma ^ we get that (X,r,0) ^ (Qoi A ... A 0"'o»n)^0'"^C 



for all runs r ^ IZ. By BCS5, this is true if and only if V\a{'R,[true,oi, . . . ,0m]) > -L 
and FlaiTZ[true,oi,. .. ,Om-i,Om A C]) ^ Fla(JZ[true,oi, . . . ,Om~i,Om A ^^])- By UPD2, 
there is a sequence [sq, . . . , Sm] ^ TZ[true, oi, . . . , Om-i, Om A S^] such that Pla([so, . . . , Sm]) it 
Pla([so; ■ ■ ■ ) ^m]) ^r all [s'q, . . . , s'^] C TZ[true, oi, . . . , Om-i,Om A -1^]. Moreover, without loss 
of generality, we can assume that Pla([so, . . . , Sm]) it Pla([so) • • • > ^'m\) [sqi • • • > ^'m\ ^ 

lZ[true, oi, . . . , Om-i, Om A .^], since there are only finitely many such sequences. Thus, by 
UPD2, PI, ([so, ... , Sm]) it Pla(7^[^™e ,0\, . . . , Om\ ['So 7 • • • ) -Sm 

]). □ 

We can now prove that belief change in X corresponds to belief change in C/j. 
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Lemma A.8: Let 1 = (7^, vr, V) G Then 

States {I, Sa • tp) = mini/j^ {States {I, Sq), iV'lc/i) 
for all local states Sa and formulas ip & C^- 

Proof: Let Pl^ be the prior in Z; assume that Pl^ consistent with a distance function d. 
Let Sa = (oi, . . .,Om)- 

To show that minijj-{States{I, Sa),l'ip}ux) ^ States(I,Sa • ip), suppose that s G 
mmij^{States{I, Sa), |V'lc/i)- Thus, there is a state Sm G States{I, Sa) such that d{sm,s') 
d{sm,s) for all states s' that satisfy ip. We want to show that s € States(I, Sa • 
Ip). From Lemma A.7| , it follows that, since Sm € States{I, Sa), there is a sequence 



such that [so,...,Sm] G Tl[true,oi,...,Om-i,Om] and Pla([so> • • • > ^m]) ^ 
Pla(7^[^rue, oi,...,Om-i,o.m] - [sq, . . . , s^]). We now show that Fla{[so, . . . , Sm, s]) it 



Fla{TZ[true,oi, . . . ,Om,''P] — [so, ■ ■ ■ , Sm, s]). By Lemma A.7 , this suffices to show that 
s G States(I, Sa • ip)- Suppose that [s'q, . . . , s^+i] ^ 7^[irite, oi, . . . , Om, "0] ~ [^O; • • • > ^m, s]. 
If [so, . . . , Sm] = [s'q, ■ ■ ■ , s'^], then we have that d{s'^, s^+i) 5^ ^^(sm, s). Since PIq is con- 
sistent with d, it follows that Pla([so, ■■■ ,Sm, s]) ft Pla([So, ■■■ ,Sm, s'ra+l])- If [so, • • • , Sm] 7^ 

[sg, . . . , sj„], then, since Pla([so, • • • , Sm]) Pla([so5 • • • , s^]) and Pl^ is consistent with d, 
we have that Pla([so, • • • , s^, s]) ft Pla([so, • • • , s^, s^+J). 

Since Pla([so, • • • , s^, s]) ft Plallsf,, . . . , s^, s^^+J) 

for all [sg, . . . , C 7^[true, oi, . . . , Om, V'] ~ [so, • • • > Sm, s] and PIq is prefix-defined, we 



have that Pla([so, • • • , Sm, s]) ft Pla(7^[irMe, oi, . . . , o^, ■0] - [sq, . . . , s^, s]. By Lemma [O, 
s G States{I, Sa ■ ip), as desired. 

To show that States{T,Sa ■ ip) Q mmi/^{States{I, Sa),lip}ux)i suppose that s G 
States {2, Sa- ip)- By Lemma |A.7| , there is a sequence sq, . . . ,Sm such that [sq, • • • , Sm, s]) C 
n[true,oi,...,Ojn,ip] and Pla([so, • • • , s^, s]) ft Pla(7^[^r^^e, oi, . . . , o^, ■0] - [sq, • • • , s^, s]). 
We want to show that Sm G StatesiZ, Sa) and that d{sm, s') ft d[sm, s) for all s' that satisfy 
-0. This suffices to prove that s G Ta.\nijj.{States{T,Sa), \ip\ui)- 

To show that Sm G States {Z, Sq), by Lemma |Al7| , it suffices to show that Pla([so, • • • , Sm\) ft 
Y'\a{TZ[true, oi, . . . , Om] — [sq, • • • , s^])- Let Sq, • • • , s^ be a sequence such that [s'q, . . . , s^] C 
TZ[true, oi, . . . , Om]- By definition, [sq, . . . , s^, s] C TZ[true, oi, . . . , Om, V']- Thus, from our 
choice of sq, . . . , Sm, it follows that Pla([so, • • • , Sm, s]) ft Pla([so, . . . , s'^, s]). Since Pla is 



consistent with d, it follows that Pla([so, • • • , Sm]) ft Pla([so, • • • , s^]). Thus, by Lemma A.7 , 
Sm G StatesiZ, Sa)- To see that d[sm, s') ft d{sm, s) for all s' that satisfy ip, let s' 7^ s be such 
that s' \= Ip. Thus, [sq, . . . , Sm, s'] C [true, oi, . . . , Om, From our choice of sq,. . . , Sm, 
it follows that Pla([so, . . . ,Sm,s]) ft Pla([so, . . . , Sm, s']). Since Pla is consistent with d, it 
follows that d{sm,s') ft d{sm,s). We conclude that s G mmjjj- [States [Z, s a), {ipjux)- n 

We now have the tools to prove the "if" direction of Theorem 

Lemma A. 9: If Z = (7^, 7r,'P) G , then there is a belief change operator o that satisfies 
U1-U8 such that 

BeliZ, Sa) oip = BeliZ, Sa ■ ip) 
for all local states Sa and formulas ip £ Cg. 
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Proof: Let X € CP . Using the arguments we presented above, it easy to check that \Jx 
is an update structure. By Theorem |6.1|, there is a behef change operator o that satisfies 



U1-U8 such that |</?o ■i/'Jc/i = mint/^-d^^Jf/^-, [V'lo'x) ^ ^p,tp ^ Ce- From Lemma A.8 , it 
follows that Bel(X, Sa) o ^ = Bel(X, Sa ■ □ 



We now prove the "only if" direction of Theorem |6.2| . Suppose that o is a belief change 
operator that satisfies U1-U8. According to Theorem |6.1| , there is an update structure Uo 
that corresponds to o. Thus, it suffices to show that there is a system X such that Uj = Uo. 

Lemma A. 10: Let U = {W,d,7:u) be an update structure. Then there is a system I ^ 
such that Uj = U. 

Proof: Given the sequences wo,wi, . . . &W and 01,02, . . . G Ce, let r'^o,wi,... -,01,02,... |-,g ^j^g 
run defined so that r^o,«'i,-;oi,02,.-(^) = and r^o,«'i,-;oi,02,.-(m) = (oi,...,Om). Let 
JZ = ^r^o,wi,...;oi,02,... . TTu(^Wm){om) = true for all m}. Define vr such that ■K{r,m){p) = 
■Ki/{re{m)){p) for p £ and ■K{r,m){learn{ip)) = true if 0(j,,„) = ip for if G Ce- 
lt is clear that (7^, vr) satisfies BCS1-BCS4 and UPDl. Thus, all that remains to show 
is that there is a prior plausibility measure Pl^ that satisfies UPD2-UPD4. This will ensure 
that {n,7r,V) e C^. 

We proceed as follows. We define a preferential space (TZ, ^) where r ^ r' if and only 
if there is some m such that re{k) = r'^{k) for all < A; < m, re(m + 1) ^ r'^{m + 1), and 
(i(re(m), re(m + l)) < d{r'^{m),r'^{m + \)). Recall that r ~< r' denotes that r is preferred over 
r'. Thus, this ordering is consistent with the comparison of events of the form [sq, . . . , s„] 
according to UPD2. 



Using the construction of Proposition 2^, there is a plausibility space {R, Pla) such that 
Pla(^) ^ Pla(-B) if and only if for all r B — A, there is a run r' ^ A such that r' ~< r and 
there is no r" G B — A such that r" -< r'. By (Friedman & Halpern, 1998b, Theorem 5.5), 
Pla is a qualitative plausibility measure. We now show that it satisfies UPD2-UPD4. 

We start with UPD2. To show that PIa is consistent with d, we need to show that 
Pla([soi ■ ■ ■ ,Sn]) < P^aiWo, . . . , s^]) if and only if there is some m < n such that Sk = s'j^ 
for all < /c < ni, and d{smi Sm+i 

) > d(s^,,s^_^i). Suppose that P1q([so, . . . , s^]) < 
Pla([so, . . . , s^]). Let r be some run in [sq, . . . ]. Without loss of generality we can assume 
that re(m) = re(n) for all m > n. Since Pla([so, . . . , s^]) < Pla([so, . . . , s^]), there is a run 
r' £ [sq, . . . , s^] such that r' ~< r. By definition, this implies that there is an m such that 
re{k) = r'^(k) for all < /c < m, and d{r'^{m) , r'^{m + 1)) < d{re{m),re{m + 1)). We claim 
that m < n. For if m > n, then re(m + l) = re{m) by construction, so (i(re(m), re(m- + l)) = 
d{re{m),re{m)) < d{r'^{m) , r'^{m + 1)) and r' 7^ r, a contradiction. Thus, Sk = for all 
< A: < m, (i(s^,s^+i) < d{sm,Sm+i)- 

For the converse, suppose that there is an m < n such that Sk = for all < A; < m, 
and d{s'^, s'^^i) < d{sm, Sm+i)- Let r' be the run where r'^{k) = s'^ for k < n, r'^{k) = s'^ 
for k > n, and 0(r/^fc) = true for all k. It follows r' ~< r for all runs r' € [sq, . . . , s™]. Thus, 

Pla([sO,...,Sn]) <Pla(K,...,4]). 

To show that Pla is prefix-defined, we must show that Pla{TZ[(po, ■ ■ ■ , ipn]) > P^a{TZ[ipo, ■ ■ ■ 1 V'n]) 
if and only if for all [sq, . . . , s„] C TZ[ipo, . . . , ipn] — T^i'^o, • • • , ^n], there is some [s'q, . . . , s^] C 
7^[99o, • • • ,¥'n] such that Pla(K, • • -is'n]) > Pla([so, ■ ■ ■ ,s„]). Suppose that Pla(7^[(/?o, • • ■,^n]) > 
Pla(7^['^/'o, • • ■,'(pn])- Let [sq, . . . , s„] C 7^['^/'o, • • • jV'n] -'T^iv'o, • • ■,V'n]- Let r G [sq, . . . , s„] be 
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a run such that re(m) = re(n) for all m > n. Since Fla{T^[^Oi ■ ■ ■ , Vn]) > Pla(^[V'0) • • • > V'n]) 
there is a run r' G 7^[v'0) • • • > V'n] such that r' ~< r. This implies that there is an m such 
that re(fc) = rg(A:) for all < A; < m, and d{r'^{m) , r'^{m + 1)) < d{re{m),re{m + 1)). 
As before, we have that m < n, and thus Pla([rg(0), . . . , r'^{n)]) > Pla([so, . . . , s„]). Since 
r' £ TZl^po, ■ ■ ■ , (fn], we also have that [rg(0), . . . , r'^{n)] C TZ[ipo, . . . , (/?„], as desired. 

For the converse, assume that for all [sq, . . . , s„] C TZlipo, . . . , ipn] — T^[^o, • • • , fn] there 
is some [s'q, ...,s'^]C K[ipo, . . . , such that Pla([so, • • • , s'^]) > Pla([so, • • • , Sn])- This im- 
plies that Pla(7^[v7o, • • • , ^n]) > Pla([so, • • • , Sn]) for all for all [sq, ...,Sn] ^ Tl[ipo, ■■■ ,tpn]- 
Tl[ipo, ■ ■ ■ , ^n]- Since there are only finitely many sequences of states of length m, we can ap- 
ply A2, and conclude that Fla{TZ[ipo, ■■■ ,V^n]) > Pla(^[V'o, • • • , V'n] - T^lfo, ■■■ , V'n])- Thus, 

Pl„(7^[^0, ■ ■ • , ^n]) > Plaimo, . . . , V'n])). 



For UPD3, recall that the construction of Proposition 2^ is such that Pla(-R) > _L for 
all non-empty R TZ. Since, by our construction, the set TZ[(po, ■ ■ ■ , ^n] is non-empty for 
all sequences ipQ, . . . ,ipn of consistent formulas, UPD3 must hold. 

Finally, we consider UPD4. We have to show that Fla{TZ[^po, ■ ■ ■ , ^n+i', oi, . . . , On]) > 
Pla(7^[V'o, • • ■,ipn+i;oi,.. .,On]) if and Only if Pla(7l[93o , 9^1 Aoi , . . . , (/7„Ao„, (/j„+i]) > Pla(7e[V'o, "01 A 
01, . . . , V'nAOn, V'n+i])- By Construction, 7^[(/?o, • • .,(pn+i;oi, . . . , o„] C TZ[ipo,(piAoi, . . .,(pnA 
On, ^n+i]- On the other hand, for each run r £ TZ[ipo, Vi A oi, A o„, ^fn+i] there is 

a run r' £ TZl^po, ■ ■ ■ i fn+i]Oi, . . . ,On] such that r'^{m) = re{m) for all m, and 0(.r^m) = Om 
for 1 < m < n. Since the preference ordering on runs is a function only of the environ- 
ment states, it is clear that r and r' are compared in the same manner; that is for all 
r" , r" ^ r if and only if r" -< r', and r -< r" if and only if r' -< r" . Thus, we conclude 
that for the purposes of the preference ordering, both TZ[ipo, (^i A oi, . . . , A On, ^n+i] and 
TZ[(pQ, . . . , (/7n+i; oi, . . . , On] are compared in the same manner to other sets. It easy to see 
that this suffices to show that Pla satisfies UPD4. □ 



Finally, we can prove Theorem S.2 



Theorem |6.2| : A belief change operator o satisfies U1-U8 if and only if there is a system 
I € such that 

Bel(I, Sa) oip = Bel{I, Sa ■ ip) 
for all epistemic states Sa and formulas ip £ Ce- 



Proof: The "if" direction follows from Lemma A. 9. For the "only if" direction, assume that 
o satisfies U1-U8. By Theorem |6.1| , there is an update structure C/o such that [(/jo-^J^/j. = 
miuf/j-d^jjf/^-, I^Il^i) for all ip^'il) £ L^- By Lemma A.1C| , there is a system Z £C^ such that 



Uj = [/<>• From Lemma [A.8| , it follows that Bel(T, Sa) oip = Bel(T, Sa ■ V') for all local states 
Sa and formulas ip £ Ce- □ 
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